When users are configured to use startTLS with Role-Based Access Control (RBAC) Lightweight Directory Access Protocol (LDAP), at login time, the user's credentials are sent via plaintext to the LDAP server.
This vulnerability was found by an internal audit at Puppet.
Affected Software Versions:
Resolved in: