CVE-2020-7944: Puppet Continuous Delivery
High severity, CVSS 7.7. EPSS: 0.9% chance of exploitation in the next 30 days.
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.
Affected products
- Puppet Continuous Delivery: before 3.4.0 (fixed in 3.4.0)
Published 2020-03-26. Last modified 2026-06-17.