First published: Tue Aug 20 2013(Updated: )
Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Enterprise | <=3.0.0 | |
Puppet Enterprise | =2.5.1 | |
Puppet Enterprise | =2.5.2 | |
Puppet Enterprise | =2.8.0 | |
Puppet Enterprise | =2.8.1 | |
Puppet Enterprise | =2.8.2 | |
Puppet Enterprise | =2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4964 is considered a moderate security vulnerability due to the risk of session hijacking.
To fix CVE-2013-4964, upgrade Puppet Enterprise to version 3.0.1 or later.
CVE-2013-4964 allows attackers to capture session cookies, potentially leading to unauthorized access to user sessions.
CVE-2013-4964 affects all versions of Puppet Enterprise prior to 3.0.1.
Yes, CVE-2013-4964 can be exploited remotely without authentication, making it a significant threat.