Learn about CVE-2018-11746 where Puppet Discovery versions before 1.2.0 may expose login credentials due to WinRM connections falling back to basic authentication on Windows hosts.
Puppet Discovery can leak authentication information due to a vulnerability in versions prior to 1.2.0, potentially exposing login credentials.
Understanding CVE-2018-11746
If a HTTPS server is unavailable in Puppet Discovery versions before 1.2.0, WinRM connections on Windows hosts may resort to basic authentication over insecure channels, leading to credential exposure.
What is CVE-2018-11746?
The CVE-2018-11746 vulnerability in Puppet Discovery versions before 1.2.0 allows for potential leakage of authentication information when conducting Discovery on Windows hosts.
The Impact of CVE-2018-11746
The vulnerability poses a high severity risk with a CVSS base score of 8.6, impacting confidentiality by exposing login credentials.
Technical Details of CVE-2018-11746
Puppet Discovery vulnerability details and affected systems.
Vulnerability Description
In Puppet Discovery versions prior to 1.2.0, WinRM connections on Windows hosts can fall back to basic authentication over insecure channels if a HTTPS server is not available, potentially exposing login credentials.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2018-11746 and preventing credential exposure.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates