CVE-2012-5158
published 2014-03-14CVE-2012-5158: Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
0.81%
54.5th percentile
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet_enterprise | <= 2.6.0 | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppetlabs | puppet | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_debian4.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ggqp-jmq3-2qm6: Puppet Enterprise (PE) before 2
ghsa_unreviewed·2022-05-14
CVE-2012-5158 [MEDIUM] CWE-287 GHSA-ggqp-jmq3-2qm6: Puppet Enterprise (PE) before 2
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
Debian
CVE-2012-5158: puppet - Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when t...
vendor_debian·2012·CVSS 4.0
CVE-2012-5158 [MEDIUM] CVE-2012-5158: puppet - Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when t...
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
Scope: local
bullseye: resolved
No detection rules found.
No public exploits indexed.
2014-03-14
Published