Back

MEDIUM

Cleartext Storage of Sensitive Information for Puppet Resource API

Published Jul 3, 2026

Description

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.

Affected products

Remediation

Vendor solution

Upgrade to Puppet Core 8.20.0, PE 2023.8.10, or PE 2025.11.0

Red Hat statement

Red Hat OpenStack Platform 17.1 ships rubygem-puppet-resource_api version 1.8.13, which is within the affected range (1.5.0-1.9.1). Red Hat Satellite ships puppet-agent which bundles the resource_api gem; investigation is ongoing to determine if those versions are in the affected range. The sensitive flag on resource_api parameters is not properly preserved, causing values such as passwords to be stored in cleartext in the Puppet agent's local transaction state cache.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Perforce
Published Jul 3, 2026
Updated Jul 6, 2026
Reserved May 18, 2026
CISA Vulnrichment
Updated Jul 6, 2026
NVD
Status Awaiting Analysis
Modified Jul 6, 2026
Red Hat
Severity Moderate
Public date Jul 3, 2026
ENISA EUVD
Assigner Perforce
Published Jul 3, 2026
Updated Jul 6, 2026
Exploited since n/a
EUVD-2026-41516