Severity
8.8HIGH
EPSS
0.1%
top 65.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27
Latest updateMay 24

Description

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDpuppet/puppet_enterprise3.0.02015.2.0

🔴Vulnerability Details

2
GHSA
GHSA-3pjj-89j6-25qq: Parts of the Puppet Enterprise Console 32022-05-24
CVEList
CVE-2015-5686: Parts of the Puppet Enterprise Console 32020-02-27