CVE-2021-27023 — puppet
CRITICALCVE-2021-27023 is a critical-severity (CVSS 9.8) vulnerability in puppet. A fix is available for puppet — see the affected versions and patch details below.
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2021-27023 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
puppet💎puppetReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects RubyGems packages — download data is not available via public APIs for these ecosystems.
Description
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 💎RubyGems | puppet | ≥ 7.0.0&&< 7.12.1 | 7.12.1bundle update puppet --conservative |
| 💎RubyGems | puppet | all versions | 6.25.1bundle update puppet --conservative |
Affected Products
fedorafedoraprojectpuppet agentpuppetpuppet enterprisepuppetpuppet serverpuppetDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for puppet, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update puppet to 7.12.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-27023 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
Red Hat Satellite 6.8 and earlier versions are not affected by this vulnerability.
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Satellite 6.10 for RHEL 7 | puppet-agent-0:6.26.0-1.el7sat | RHSA-2022:1708 |
| Red Hat Satellite 6.9 for RHEL 7 | puppet-agent-0:6.26.0-1.el7sat | RHSA-2022:1478 |
| Satellite Tools 6.10 for RHEL 6.ELS | puppet-agent-0:6.26.0-1.el6sat | RHSA-2022:4866 |
| Satellite Tools 6.9 for RHEL 6.ELS | puppet-agent-0:6.26.0-1.el6sat | RHSA-2022:4867 |
Frequently Asked Questions
Is CVE-2021-27023 in your dependencies?
Find it across RubyGems, including transitive dependencies.