First published: Mon Dec 11 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script or HTML via the string parameter, related to Login Redirect.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Enterprise | <2015.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2015-6502.
The severity of CVE-2015-6502 is medium with a CVSS score of 6.1.
The affected software version for CVE-2015-6502 is Puppet Enterprise before 2015.2.1.
The CWE ID for this vulnerability is CWE-79.
Yes, a fix or patch is available for CVE-2015-6502. It is recommended to update to Puppet Enterprise version 2015.2.1 or later.