First published: Thu Jan 12 2017(Updated: )
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Enterprise | <=2015.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6501 is considered a medium severity vulnerability due to its potential to facilitate phishing attacks.
To fix CVE-2015-6501, upgrade Puppet Enterprise to version 2015.2.1 or later.
CVE-2015-6501 allows attackers to redirect users to arbitrary websites, which can lead to phishing and credential theft.
Puppet Enterprise versions prior to 2015.2.1 are affected by CVE-2015-6501.
There is no official workaround for CVE-2015-6501; updating to a patched version is the recommended action.