CVE-2013-4762: Input Validation
Published Aug 20, 2013
·Updated
Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote attackers to hijack sessions by obtaining an old session ID.
Affected Software
7 affected components
puppet Puppet Enterprise<=3.0.0
puppet Puppet Enterprise=2.5.1
puppet Puppet Enterprise=2.5.2
puppet Puppet Enterprise=2.8.0
puppet Puppet Enterprise=2.8.1
puppet Puppet Enterprise=2.8.2
puppet Puppet Enterprise=2.8.3
Event History
Aug 20, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4762?
CVE-2013-4762 is classified as a high-severity vulnerability due to the potential for session hijacking.
2
How do I fix CVE-2013-4762?
To fix CVE-2013-4762, users should upgrade Puppet Enterprise to version 3.0.1 or later.
3
What vulnerabilities can result from CVE-2013-4762?
CVE-2013-4762 can result in session hijacking, allowing attackers to impersonate legitimate users.
4
Who is affected by CVE-2013-4762?
CVE-2013-4762 affects all versions of Puppet Enterprise prior to 3.0.1.
5
Is CVE-2013-4762 easily exploitable?
Yes, CVE-2013-4762 can be exploited remotely by an attacker who can obtain an old session ID.