CVE-2013-4968: XSS
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-4968?
CVE-2013-4968 is a vulnerability in Puppet Enterprise before version 3.0.1 that allows remote attackers to conduct clickjacking attacks and cross-site scripting (XSS) attacks.
How severe is CVE-2013-4968?
CVE-2013-4968 has a severity rating of 6.1, which is considered medium.
How can remote attackers exploit CVE-2013-4968?
Remote attackers can exploit CVE-2013-4968 by conducting clickjacking attacks and cross-site scripting (XSS) attacks.
Which versions of Puppet Enterprise are affected by CVE-2013-4968?
Puppet Enterprise versions between 2.0.0 and 3.0.1 are affected by CVE-2013-4968.
How can I fix CVE-2013-4968?
To fix CVE-2013-4968, you should update Puppet Enterprise to version 3.0.1 or later.