CVE-2025-10360
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-24

Last updated on: 2025-09-24

Assigner: Perforce

Description
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the user has a Puppet Enterprise Advanced license and has enabled the Infra Assistant feature. The key is used for encrypting one particular bit of data in the Infra Assistant database: the API key for their AI provider account.Β This has been fixed in Puppet Enterprise version 2025.6, and release notes for 2025.6 have remediation steps for users of affected versions who can't update to the latest version.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-24
Last Modified
2025-09-24
Generated
2026-05-07
AI Q&A
2025-09-24
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
puppet puppet_enterprise 2025.6
puppet puppet_enterprise 2025.5
puppet puppet_enterprise 2025.4.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in Puppet Enterprise versions 2025.4.0 and 2025.5 where the encryption key used to encrypt the API key for the AI provider account in the Infra Assistant database was not excluded from files gathered by Puppet backup. This means the encryption key could be exposed through backup files if the Infra Assistant feature is enabled and the user has a Puppet Enterprise Advanced license. The issue was fixed in version 2025.6.


How can this vulnerability impact me? :

If you are using Puppet Enterprise 2025.4.0 or 2025.5 with the Infra Assistant feature enabled and an Advanced license, an attacker who gains access to backup files could obtain the encryption key. This could allow them to decrypt the API key for your AI provider account stored in the Infra Assistant database, potentially leading to unauthorized access or misuse of that AI service.


What immediate steps should I take to mitigate this vulnerability?

Upgrade Puppet Enterprise to version 2025.6 where the issue is fixed. If upgrading is not immediately possible, follow the remediation steps provided in the release notes for version 2025.6 for affected versions. The vulnerability only affects systems with a Puppet Enterprise Advanced license and the Infra Assistant feature enabled, so disabling the Infra Assistant feature may reduce risk until an upgrade can be performed.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart