Puppet Cross Site Request Forgey and Information Disclosure Vulnerabilities
BID:57869
Info
Puppet Cross Site Request Forgey and Information Disclosure Vulnerabilities
| Bugtraq ID: | 57869 |
| Class: | Unknown |
| CVE: |
CVE-2013-1398 CVE-2013-1399 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2013 12:00AM |
| Updated: | Feb 06 2013 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Puppetlabs Puppet Enterprise 2.7 |
| Not Vulnerable: |
Puppetlabs Puppet Enterprise 2.7.1 |
Discussion
Puppet Cross Site Request Forgey and Information Disclosure Vulnerabilities
Puppet is prone to a cross-site request forgery and information-disclosure vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain actions in the context of an authorized user's session and to disclose sensitive information by gaining unauthorized access to the affected application; other attacks are also possible.
Puppet Enterprise 2.7.0 is vulnerable; other versions may also be affected.
Puppet is prone to a cross-site request forgery and information-disclosure vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain actions in the context of an authorized user's session and to disclose sensitive information by gaining unauthorized access to the affected application; other attacks are also possible.
Puppet Enterprise 2.7.0 is vulnerable; other versions may also be affected.
Exploit / POC
Puppet Cross Site Request Forgey and Information Disclosure Vulnerabilities
Attackers may exploit these issues through a browser. To exploit a cross-site request forgery issue, an attacker must entice an unsuspecting victim to visit a malicious webpage.
Attackers may exploit these issues through a browser. To exploit a cross-site request forgery issue, an attacker must entice an unsuspecting victim to visit a malicious webpage.
Solution / Fix
Puppet Cross Site Request Forgey and Information Disclosure Vulnerabilities
Solution:
A vendor patch is available. Please see the references for more information.
Solution:
A vendor patch is available. Please see the references for more information.
References
Puppet Cross Site Request Forgey and Information Disclosure Vulnerabilities
References:
References:
- CVE-2013-1398 -Information Disclosure (Puppet Labs)
- CVE-2013-1399 (Console CSRF Vulnerability) (Puppet Labs)
- Puppet Homepage (Puppet Labs)