PT-2017-7408 · Puppet · Puppet Enterprise
Publicado
2017-12-11
·
Atualizado
2022-01-24
·
CVE-2015-8470
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Puppet Enterprise versions 3.7.x through 3.8.x and 2015.2.x
Description
The issue is related to the console in Puppet Enterprise not setting the secure flag for the
JSESSIONID cookie in an HTTPS session. This makes it easier for remote attackers to capture the cookie by intercepting its transmission within an HTTP session.Recommendations
For Puppet Enterprise versions 3.7.x, 3.8.x, and 2015.2.x, consider updating the configuration to set the secure flag for the
JSESSIONID cookie in HTTPS sessions to prevent interception.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Puppet Enterprise