CVE-2013-4961
published 2013-08-20CVE-2013-4961: Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote…
PriorityP420medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.80%
77.0th percentile
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet_enterprise | <= 3.0.0 | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-4961: puppet - Puppet Enterprise before 3.0.1 includes version information for the Apache and P...
vendor_debian·2013·CVSS 5.0
CVE-2013-4961 [MEDIUM] CVE-2013-4961: puppet - Puppet Enterprise before 3.0.1 includes version information for the Apache and P...
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
Scope: local
bullseye: resolved
GHSA
GHSA-qxqc-6rp4-9rh5: Puppet Enterprise before 3
ghsa_unreviewed·2022-05-14
CVE-2013-4961 [MEDIUM] CWE-200 GHSA-qxqc-6rp4-9rh5: Puppet Enterprise before 3
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-08-20
Published