#1141432 ruby-puppet-resource-api: CVE-2026-8804

Package:
src:ruby-puppet-resource-api
Source:
src:ruby-puppet-resource-api
Submitter:
Salvatore Bonaccorso
Date:
2026-07-24 14:23:02 UTC
Severity:
normal
Tags:
#1141432#5
Date:
2026-07-04 15:06:21 UTC
From:
To:
Hi,

The following vulnerability was published for ruby-puppet-resource-api.

CVE-2026-8804[0]:
| Puppet resource_api (shipped in Puppet Core 8.x and Puppet
| Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag
| on parameters defined via the resource-api, causing values such as
| passwords to be stored in cleartext in the agent's local transaction
| state cache. Affected versions of the resource_api module include
| all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in
| puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0
| and PE 2023.8.10 & PE 2025.11.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-8804
https://www.cve.org/CVERecord?id=CVE-2026-8804
[1] https://github.com/puppetlabs/puppet-resource_api/pull/384
[2] https://github.com/puppetlabs/puppet-resource_api/commit/87737def98e5b299fcd78b198159bca88be991e7

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1141432#12
Date:
2026-07-24 14:20:12 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
ruby-puppet-resource-api, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141432@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jérôme Charaoui <jerome@riseup.net> (supplier of updated ruby-puppet-resource-api package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 24 Jul 2026 09:26:49 -0400
Source: ruby-puppet-resource-api
Architecture: source
Version: 2.0.1-1
Distribution: unstable
Urgency: medium
Maintainer: Puppet Package Maintainers <pkg-puppet-devel@alioth-lists.debian.net>
Changed-By: Jérôme Charaoui <jerome@riseup.net>
Closes: 1141432
Changes:
 ruby-puppet-resource-api (2.0.1-1) unstable; urgency=medium
 .
   * New upstream version 2.0.1, fixes CVE-2026-8804 (Closes: #1141432)
   * switch package upstream to OpenVoxProject
Checksums-Sha1:
 4f2ac18ed7aae6720a68cc23bd66a682f8dbf657 1516 ruby-puppet-resource-api_2.0.1-1.dsc
 4f30f65d9d1702b5878769b453af982cef05597b 142756 ruby-puppet-resource-api_2.0.1.orig.tar.xz
 65ba40fe4fcaa78b1ea7c6705ed5263a4ad07d83 2516 ruby-puppet-resource-api_2.0.1-1.debian.tar.xz
 f8bd5b33137fdddbfa938174a21e236fd943649f 5886 ruby-puppet-resource-api_2.0.1-1_amd64.buildinfo
Checksums-Sha256:
 112bcc31b829fd4a9c57fccbcbf3f17d862764926f4ed3152908a68af60b5b4d 1516 ruby-puppet-resource-api_2.0.1-1.dsc
 c060ba7ea90acd708cc16f91cf4b905d3e5ef820a05266b06fab11a246d26640 142756 ruby-puppet-resource-api_2.0.1.orig.tar.xz
 24623839ca64799843538e6560750051aeb837b546a1e90e0b2bd48cd2e585f5 2516 ruby-puppet-resource-api_2.0.1-1.debian.tar.xz
 80fe9f3495ef3fc8c598b653ca513cb67415a88079f13e2472a8ad5ed537b62a 5886 ruby-puppet-resource-api_2.0.1-1_amd64.buildinfo
Files:
 b7eda7ad9f1612aa69a462016ede1cfe 1516 ruby optional ruby-puppet-resource-api_2.0.1-1.dsc
 a7d1bdc4e15261a7901cf14277d28ccc 142756 ruby optional ruby-puppet-resource-api_2.0.1.orig.tar.xz
 7b4fdbe9ae72bac2368464fdaea7fba7 2516 ruby optional ruby-puppet-resource-api_2.0.1-1.debian.tar.xz
 a746233fe2a32ebdf2da3f52ef72398e 5886 ruby optional ruby-puppet-resource-api_2.0.1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQTAq04Rv2xblqv/eu5pxS9ljpiFQgUCamNxpwAKCRBpxS9ljpiF
QrImAP9bovTVoME4tZ0r6yVlW7D8zU1JTpOw2k0gkULmPLdqsAD+NcGXEpC3syQU
dnI73gt+VkttQn5Ewh1Hx5HRr2OHawo=
=m2ve
-----END PGP SIGNATURE-----