Perforce Puppet Core是美国Perforce公司的一款配置管理自动化工具。 Perforce Puppet Core存在加密问题漏洞,该漏洞源于resource_api未保留通过resource-api定义的参数的敏感标志,导致密码等值以明文形式存储在代理的本地事务状态缓存中。以下版本受到影响:Puppet Core 8.0.0至8.10.0版本,8.11.0至8.19.0版本;Puppet Enterprise 2023.8.0至2023.8.9版本,2025.0.0至2025.10.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Perforce | Puppet Core | 8.11.0≤ 8.19.0 |
affected |
8.0.0≤ 8.10.0 |
affected | ||
8.20.0 |
unaffected | ||
| Perforce | Puppet Enterprise | 2023.8.0≤ 2023.8.9 |
affected |
2025.0.0≤ 2025.10.0 |
affected | ||
2023.8.10 |
unaffected | ||
2025.11.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Perforce | Puppet Core | 8.11.0 ~ 8.19.0 | - |
|
| Perforce | Puppet Enterprise | 2023.8.0 ~ 2023.8.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet