6.1
CVSSv3

CVE-2016-5715

Published: 12/01/2017 Updated: 24/01/2022
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6501.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise

Exploits

Puppet Enterprise Web Interface versions prior to 201640 suffer from an open redirection vulnerability ...