5
CVSSv2

CVE-2013-2716

Published: 10/04/2013 Updated: 10/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Puppet Labs Puppet Enterprise prior to 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1.2.x or 2.0.x versions, which allows remote malicious users to obtain console access via a crafted cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2.5.2

puppetlabs puppet 2.6.0

puppet puppet enterprise 2.5.1

puppetlabs puppet 2.5.0

puppet puppet enterprise

puppetlabs puppet 1.1.0

puppetlabs puppet 1.0.0

puppet puppet enterprise 2.0.0

puppetlabs puppet 1.2.0