cbcvebase.
CVE-2013-4963
published 2014-03-14

CVE-2013-4963: Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianpuppet
puppetpuppet_enterprise<= 3.0.0
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise