PT-2014-2880 · Puppet · Puppet Enterprise

Published

2014-03-14

·

Updated

2019-07-10

·

CVE-2013-4963

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Puppet Enterprise (PE) versions prior to 3.0.1
Description The issue affects Puppet Enterprise, allowing remote attackers to hijack user authentication for various requests, including deleting reports, groups, or classes, potentially having other unspecified impacts.
Recommendations For versions prior to 3.0.1, update to version 3.0.1 or later to resolve the issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4963

Affected Products

Puppet Enterprise