CVE-2013-4959
published 2013-08-20CVE-2013-4959: Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
28.0th percentile
Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet_enterprise | <= 3.0.0 | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-4959: puppet - Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive inform...
vendor_debian·2013·CVSS 2.1
CVE-2013-4959 [LOW] CVE-2013-4959: puppet - Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive inform...
Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.
Scope: local
bullseye: resolved
GHSA
GHSA-mv55-69wx-g2jm: Puppet Enterprise before 3
ghsa_unreviewed·2022-05-14
CVE-2013-4959 [LOW] CWE-200 GHSA-mv55-69wx-g2jm: Puppet Enterprise before 3
Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-08-20
Published