First published: Fri Mar 14 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Puppet Dashboard | =1.0.0 | |
Puppet Puppet Dashboard | =1.0.3 | |
Puppet Puppet Dashboard | =1.0.4 | |
Puppet Puppet Dashboard | =1.1.0 | |
Puppet Puppet Dashboard | =1.1.1 | |
Puppet Puppet Dashboard | =1.2.0 | |
Puppet Puppet Dashboard | =1.2.1 | |
Puppet Puppet Dashboard | =1.2.2 | |
Puppet Puppet Dashboard | =1.2.3 | |
Puppet Puppet Dashboard | =1.2.4 | |
Puppet Enterprise | =1.0 | |
Puppet Enterprise | =1.1 | |
Puppet Enterprise | =1.2.0 | |
Puppet Enterprise | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0891 has a medium severity rating due to its potential for allowing cross-site scripting attacks.
To fix CVE-2012-0891, upgrade Puppet Dashboard and Puppet Enterprise to version 1.2.5 or later.
CVE-2012-0891 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary scripts or HTML.
Puppet Dashboard versions 1.0 through 1.2.4 are affected by CVE-2012-0891.
Puppet Enterprise versions 1.0 through 1.2.4 are vulnerable to CVE-2012-0891.