First published: Fri Mar 14 2014(Updated: )
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Enterprise | <=2.6.0 | |
Puppet Enterprise | =2.0.0 | |
Puppet Enterprise | =2.5.1 | |
Puppet Enterprise | =2.5.2 | |
Puppet | =2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5158 is classified as a medium severity vulnerability due to its potential impact on authenticated user sessions.
To fix CVE-2012-5158, you should upgrade Puppet Enterprise to version 2.6.1 or later.
CVE-2012-5158 allows remote authenticated users to retain access even after the session secret changes, potentially leading to unauthorized access.
Puppet Enterprise versions prior to 2.6.1, including 2.5.0, 2.5.1, 2.5.2, and 2.0.0, are affected by CVE-2012-5158.
Yes, CVE-2012-5158 can potentially be exploited remotely by authenticated users.