Puppet CVE-2013-4964 Session Fixation Vulnerability
BID:61856
Info
Puppet CVE-2013-4964 Session Fixation Vulnerability
| Bugtraq ID: | 61856 |
| Class: | Unknown |
| CVE: |
CVE-2013-4964 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2013 12:00AM |
| Updated: | Mar 19 2015 09:34AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Puppet Labs Puppet Enterprise 2.5.1 Puppet Labs Puppet Enterprise 2.0.3 Puppet Labs Puppet Enterprise 2.0.2 Puppet Labs Puppet Enterprise 2.6 Puppet Labs Puppet Enterprise 1.2 Puppet Labs Puppet Enterprise 1.1 Puppet Labs Puppet Enterprise 1.0 Puppet Labs Puppet Enterprise 2.0 |
| Not Vulnerable: | |
Discussion
Puppet CVE-2013-4964 Session Fixation Vulnerability
Puppet is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Versions prior to Puppet Enterprise 3.0.1 are vulnerable.
Puppet is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Versions prior to Puppet Enterprise 3.0.1 are vulnerable.
Exploit / POC
Puppet CVE-2013-4964 Session Fixation Vulnerability
To exploit this issue an attacker entices an unsuspecting user into following a malicious URI.
To exploit this issue an attacker entices an unsuspecting user into following a malicious URI.