CVE-2018-11748: Puppet Device Manager

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.

Affected products

  • Puppet Device Manager: before 2.7.0 (fixed in 2.7.0)

Published 2018-10-02. Last modified 2026-06-17.