CVE-2013-4964: Medium severity puppet enterprise vulnerability
Published Aug 20, 2013
·Updated
Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected Software
7 affected components
puppet Puppet Enterprise<=3.0.0
puppet Puppet Enterprise=2.5.1
puppet Puppet Enterprise=2.5.2
puppet Puppet Enterprise=2.8.0
puppet Puppet Enterprise=2.8.1
puppet Puppet Enterprise=2.8.2
puppet Puppet Enterprise=2.8.3
Event History
Aug 20, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4964?
CVE-2013-4964 is considered a moderate security vulnerability due to the risk of session hijacking.
2
How do I fix CVE-2013-4964?
To fix CVE-2013-4964, upgrade Puppet Enterprise to version 3.0.1 or later.
3
What impact does CVE-2013-4964 have on my application?
CVE-2013-4964 allows attackers to capture session cookies, potentially leading to unauthorized access to user sessions.
4
Who is affected by CVE-2013-4964?
CVE-2013-4964 affects all versions of Puppet Enterprise prior to 3.0.1.
5
Is CVE-2013-4964 exploitable remotely?
Yes, CVE-2013-4964 can be exploited remotely without authentication, making it a significant threat.