CVE-2012-0891: XSS
Published Mar 14, 2014
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.
Affected Software
14 affected components
Puppet Puppet Dashboard=1.0.0
Puppet Puppet Dashboard=1.0.3
Puppet Puppet Dashboard=1.0.4
Puppet Puppet Dashboard=1.1.0
Puppet Puppet Dashboard=1.1.1
Puppet Puppet Dashboard=1.2.0
Puppet Puppet Dashboard=1.2.1
Puppet Puppet Dashboard=1.2.2
Puppet Puppet Dashboard=1.2.3
Puppet Puppet Dashboard=1.2.4
Puppet Puppet Enterprise=1.0
Puppet Puppet Enterprise=1.1
Puppet Puppet Enterprise=1.2.0
Puppet Puppet Enterprise=2.0.0
Event History
Mar 14, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-0891?
CVE-2012-0891 has a medium severity rating due to its potential for allowing cross-site scripting attacks.
2
How do I fix CVE-2012-0891?
To fix CVE-2012-0891, upgrade Puppet Dashboard and Puppet Enterprise to version 1.2.5 or later.
3
What types of attacks can CVE-2012-0891 facilitate?
CVE-2012-0891 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary scripts or HTML.
4
Which versions of Puppet Dashboard are affected by CVE-2012-0891?
Puppet Dashboard versions 1.0 through 1.2.4 are affected by CVE-2012-0891.
5
Which versions of Puppet Enterprise are vulnerable to CVE-2012-0891?
Puppet Enterprise versions 1.0 through 1.2.4 are vulnerable to CVE-2012-0891.