2.1
CVSSv2

CVE-2013-4959

Published: 20/08/2013 Updated: 10/07/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Puppet Enterprise prior to 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise

puppet puppet enterprise 2.8.3

puppet puppet enterprise 2.8.1

puppet puppet enterprise 2.5.2

puppet puppet enterprise 2.8.2

puppet puppet enterprise 2.8.0

puppet puppet enterprise 2.5.1