First published: Tue Aug 20 2013(Updated: )
Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Enterprise | <=3.0.0 | |
Puppet Enterprise | =2.5.1 | |
Puppet Enterprise | =2.5.2 | |
Puppet Enterprise | =2.8.0 | |
Puppet Enterprise | =2.8.1 | |
Puppet Enterprise | =2.8.2 | |
Puppet Enterprise | =2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4958 is considered a high severity vulnerability due to its potential to allow unauthorized access through an unattended workstation.
To mitigate CVE-2013-4958, upgrade Puppet Enterprise to version 3.0.1 or later, which includes session timeout features.
Puppet Enterprise versions before 3.0.1, specifically 2.5.1, 2.5.2, 2.8.0, 2.8.1, 2.8.2, and 2.8.3, are affected by CVE-2013-4958.
CVE-2013-4958 allows attackers to exploit unattended workstations to gain unauthorized privileges, posing a significant security risk.
As a temporary measure, users should ensure that workstations are logged out or locked when unattended to help mitigate the risks associated with CVE-2013-4958.