PT-2020-7869 · Puppet · Puppet Enterprise Console
Published
2020-02-27
·
Updated
2020-03-02
·
CVE-2015-5686
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Puppet Enterprise Console versions 3.x
Description:
The issue allows an attacker to perform clickjacking and CSRF (Cross-Site Request Forgery) attacks, potentially redirecting user input to an untrusted site or hijacking a user session.
Recommendations:
For Puppet Enterprise Console versions 3.x, consider implementing additional security measures to prevent CSRF attacks, such as validating user requests and ensuring that all user interactions are properly authenticated. As a temporary workaround, restrict access to sensitive areas of the console to minimize the risk of exploitation.
Fix
CSRF
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Puppet Enterprise Console