5
CVSSv2

CVE-2013-4964

Published: 20/08/2013 Updated: 10/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Puppet Enterprise prior to 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote malicious users to capture this cookie by intercepting its transmission within an http session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise

puppet puppet enterprise 2.8.3

puppet puppet enterprise 2.5.1

puppet puppet enterprise 2.8.2

puppet puppet enterprise 2.8.0

puppet puppet enterprise 2.8.1

puppet puppet enterprise 2.5.2