CVE-2018-11748: Puppet Device Manager
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.
Affected products
- Puppet Device Manager: before 2.7.0 (fixed in 2.7.0)
Published 2018-10-02. Last modified 2026-06-17.