PT-2017-7408 · Puppet · Puppet Enterprise

Publicado

2017-12-11

·

Atualizado

2022-01-24

·

CVE-2015-8470

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Puppet Enterprise versions 3.7.x through 3.8.x and 2015.2.x
Description The issue is related to the console in Puppet Enterprise not setting the secure flag for the JSESSIONID cookie in an HTTPS session. This makes it easier for remote attackers to capture the cookie by intercepting its transmission within an HTTP session.
Recommendations For Puppet Enterprise versions 3.7.x, 3.8.x, and 2015.2.x, consider updating the configuration to set the secure flag for the JSESSIONID cookie in HTTPS sessions to prevent interception. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8470

Produtos afetados

Puppet Enterprise