Security Advisory
CVE-2018-11746
8.6
HIGH
Vulnerability Description
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.
Published Date
July 3, 2018
Official Source
NIST NVD Advisory