PT-2020-7869 · Puppet · Puppet Enterprise Console

Published

2020-02-27

·

Updated

2020-03-02

·

CVE-2015-5686

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Puppet Enterprise Console versions 3.x
Description: The issue allows an attacker to perform clickjacking and CSRF (Cross-Site Request Forgery) attacks, potentially redirecting user input to an untrusted site or hijacking a user session.
Recommendations: For Puppet Enterprise Console versions 3.x, consider implementing additional security measures to prevent CSRF attacks, such as validating user requests and ensuring that all user interactions are properly authenticated. As a temporary workaround, restrict access to sensitive areas of the console to minimize the risk of exploitation.

Fix

CSRF

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5686

Affected Products

Puppet Enterprise Console