Your message dated Fri, 24 Jul 2026 14:20:12 +0000
with message-id <[email protected]>
and subject line Bug#1141432: fixed in ruby-puppet-resource-api 2.0.1-1
has caused the Debian Bug report #1141432,
regarding ruby-puppet-resource-api: CVE-2026-8804
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141432: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141432
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ruby-puppet-resource-api
Version: 1.9.0-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/puppetlabs/puppet-resource_api/pull/384
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for ruby-puppet-resource-api.
CVE-2026-8804[0]:
| Puppet resource_api (shipped in Puppet Core 8.x and Puppet
| Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag
| on parameters defined via the resource-api, causing values such as
| passwords to be stored in cleartext in the agent's local transaction
| state cache. Affected versions of the resource_api module include
| all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in
| puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0
| and PE 2023.8.10 & PE 2025.11.0.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-8804
https://www.cve.org/CVERecord?id=CVE-2026-8804
[1] https://github.com/puppetlabs/puppet-resource_api/pull/384
[2]
https://github.com/puppetlabs/puppet-resource_api/commit/87737def98e5b299fcd78b198159bca88be991e7
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: ruby-puppet-resource-api
Source-Version: 2.0.1-1
Done: Jérôme Charaoui <[email protected]>
We believe that the bug you reported is fixed in the latest version of
ruby-puppet-resource-api, which is due to be installed in the Debian FTP
archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jérôme Charaoui <[email protected]> (supplier of updated
ruby-puppet-resource-api package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 24 Jul 2026 09:26:49 -0400
Source: ruby-puppet-resource-api
Architecture: source
Version: 2.0.1-1
Distribution: unstable
Urgency: medium
Maintainer: Puppet Package Maintainers
<[email protected]>
Changed-By: Jérôme Charaoui <[email protected]>
Closes: 1141432
Changes:
ruby-puppet-resource-api (2.0.1-1) unstable; urgency=medium
.
* New upstream version 2.0.1, fixes CVE-2026-8804 (Closes: #1141432)
* switch package upstream to OpenVoxProject
Checksums-Sha1:
4f2ac18ed7aae6720a68cc23bd66a682f8dbf657 1516
ruby-puppet-resource-api_2.0.1-1.dsc
4f30f65d9d1702b5878769b453af982cef05597b 142756
ruby-puppet-resource-api_2.0.1.orig.tar.xz
65ba40fe4fcaa78b1ea7c6705ed5263a4ad07d83 2516
ruby-puppet-resource-api_2.0.1-1.debian.tar.xz
f8bd5b33137fdddbfa938174a21e236fd943649f 5886
ruby-puppet-resource-api_2.0.1-1_amd64.buildinfo
Checksums-Sha256:
112bcc31b829fd4a9c57fccbcbf3f17d862764926f4ed3152908a68af60b5b4d 1516
ruby-puppet-resource-api_2.0.1-1.dsc
c060ba7ea90acd708cc16f91cf4b905d3e5ef820a05266b06fab11a246d26640 142756
ruby-puppet-resource-api_2.0.1.orig.tar.xz
24623839ca64799843538e6560750051aeb837b546a1e90e0b2bd48cd2e585f5 2516
ruby-puppet-resource-api_2.0.1-1.debian.tar.xz
80fe9f3495ef3fc8c598b653ca513cb67415a88079f13e2472a8ad5ed537b62a 5886
ruby-puppet-resource-api_2.0.1-1_amd64.buildinfo
Files:
b7eda7ad9f1612aa69a462016ede1cfe 1516 ruby optional
ruby-puppet-resource-api_2.0.1-1.dsc
a7d1bdc4e15261a7901cf14277d28ccc 142756 ruby optional
ruby-puppet-resource-api_2.0.1.orig.tar.xz
7b4fdbe9ae72bac2368464fdaea7fba7 2516 ruby optional
ruby-puppet-resource-api_2.0.1-1.debian.tar.xz
a746233fe2a32ebdf2da3f52ef72398e 5886 ruby optional
ruby-puppet-resource-api_2.0.1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQTAq04Rv2xblqv/eu5pxS9ljpiFQgUCamNxpwAKCRBpxS9ljpiF
QrImAP9bovTVoME4tZ0r6yVlW7D8zU1JTpOw2k0gkULmPLdqsAD+NcGXEpC3syQU
dnI73gt+VkttQn5Ewh1Hx5HRr2OHawo=
=m2ve
-----END PGP SIGNATURE-----
pgppgBPR8TiVn.pgp
Description: PGP signature
--- End Message ---