5.8
CVSSv2

CVE-2013-4762

Published: 20/08/2013 Updated: 10/07/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Puppet Enterprise prior to 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote malicious users to hijack sessions by obtaining an old session ID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise

puppet puppet enterprise 2.8.3

puppet puppet enterprise 2.8.2

puppet puppet enterprise 2.8.1

puppet puppet enterprise 2.5.2

puppet puppet enterprise 2.8.0

puppet puppet enterprise 2.5.1