CVE-2015-6502: XSS
Published Dec 11, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script or HTML via the string parameter, related to Login Redirect.
Affected Software
1 affected component
puppet Puppet Enterprise<2015.2.1
Event History
Dec 11, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2015-6502.
2
What is the severity of CVE-2015-6502?
The severity of CVE-2015-6502 is medium with a CVSS score of 6.1.
3
What is the affected software version for CVE-2015-6502?
The affected software version for CVE-2015-6502 is Puppet Enterprise before 2015.2.1.
4
What is the CWE (Common Weakness Enumeration) ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
Is there a fix or patch available for CVE-2015-6502?
Yes, a fix or patch is available for CVE-2015-6502. It is recommended to update to Puppet Enterprise version 2015.2.1 or later.