First published: Wed Dec 11 2019(Updated: )
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Puppet Enterprise | >=2.0.0<3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4968 is a vulnerability in Puppet Enterprise before version 3.0.1 that allows remote attackers to conduct clickjacking attacks and cross-site scripting (XSS) attacks.
CVE-2013-4968 has a severity rating of 6.1, which is considered medium.
Remote attackers can exploit CVE-2013-4968 by conducting clickjacking attacks and cross-site scripting (XSS) attacks.
Puppet Enterprise versions between 2.0.0 and 3.0.1 are affected by CVE-2013-4968.
To fix CVE-2013-4968, you should update Puppet Enterprise to version 3.0.1 or later.