CVE-2012-5158Improper Authentication in Enterprise

Severity
4.0MEDIUMNVD
EPSS
0.2%
top 63.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14
Latest updateMay 14

Description

Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-ggqp-jmq3-2qm6: Puppet Enterprise (PE) before 22022-05-14
CVEList
CVE-2012-5158: Puppet Enterprise (PE) before 22014-03-14

📋Vendor Advisories

1
Debian
CVE-2012-5158: puppet - Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when t...2012

💬Community

1
Bugzilla
CVE-2012-4418 axis2: vulnerable to XML signature wrapping attacks2012-09-12
CVE-2012-5158 — Improper Authentication in Enterprise | cvebase