Puppet Dashboard CVE-2012-0891 Multiple Cross Site Scripting Vulnerabilities
BID:66602
Info
Puppet Dashboard CVE-2012-0891 Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 66602 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0891 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2014 12:00AM |
| Updated: | Mar 19 2015 08:09AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Puppet Labs Puppet Enterprise 1.2 Puppet Labs Puppet Enterprise 1.1 Puppet Labs Puppet Enterprise 1.0 Puppet Labs Puppet Enterprise 2.0 |
| Not Vulnerable: | |
Discussion
Puppet Dashboard CVE-2012-0891 Multiple Cross Site Scripting Vulnerabilities
Puppet Dashboard is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Puppet Dashboard is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Solution / Fix
Puppet Dashboard CVE-2012-0891 Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Puppet Dashboard CVE-2012-0891 Multiple Cross Site Scripting Vulnerabilities
References:
References:
- CVE-2012-0891 Overview (Puppet Labs)
- Puppet Dashboard Homepage (Puppet Labs)