Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:puppet:puppet_enterprise:2.6.1:*:*:*:*:*:*:*
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2013-2716 |
Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1.2.x or 2.0.x versions, which allows remote attackers to obtain console access via a crafted cookie. Published: April 10, 2013; 11:55:15 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |