4
CVSSv2

CVE-2012-5158

Published: 14/03/2014 Updated: 10/07/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Puppet Enterprise (PE) prior to 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2.0.0

puppet puppet enterprise

puppet puppet enterprise 2.5.2

puppet puppet enterprise 2.5.1

puppetlabs puppet 2.5.0