cbcvebase.
CVE-2018-6511
published 2018-05-08

CVE-2018-6511: A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Enterprise Console. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianpuppet
puppetpuppet_enterprise< 2017.3.62017.3.6
puppetpuppet_enterprise>= 2017.3.x < 2017.3.62017.3.6