CVE-2018-11746: Puppet Discovery

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.

Affected products

  • Puppet Discovery: before 1.2.0 (fixed in 1.2.0)

Published 2018-07-03. Last modified 2026-06-17.