Puppet Enterprise 'service' Parameter Open Redirection Vulnerability
BID:61949
Info
Puppet Enterprise 'service' Parameter Open Redirection Vulnerability
| Bugtraq ID: | 61949 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4955 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2013 12:00AM |
| Updated: | Mar 19 2015 08:41AM |
| Credit: | Puppet Labs |
| Vulnerable: |
Puppet Labs Puppet Enterprise 2.5.1 Puppet Labs Puppet Enterprise 2.0.3 Puppet Labs Puppet Enterprise 2.0.2 Puppet Labs Puppet Enterprise 2.6 Puppet Labs Puppet Enterprise 1.2 Puppet Labs Puppet Enterprise 1.1 Puppet Labs Puppet Enterprise 1.0 Puppet Labs Puppet Enterprise 2.0 |
| Not Vulnerable: | |
Discussion
Puppet Enterprise 'service' Parameter Open Redirection Vulnerability
Puppet Enterprise is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Puppet Enterprise versions prior to 3.0.1 are vulnerable.
Puppet Enterprise is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Puppet Enterprise versions prior to 3.0.1 are vulnerable.
Exploit / POC
Puppet Enterprise 'service' Parameter Open Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to following a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to following a malicious URI.
Solution / Fix
Puppet Enterprise 'service' Parameter Open Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Puppet Enterprise 'service' Parameter Open Redirection Vulnerability
References:
References:
- Puppet Homepage (Puppet Labs)
- CVE-2013-4955 (Phishing Through URL Redirection Vulnerability) (Puppet Labs)