First published: Mon Dec 11 2017(Updated: )
The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Enterprise | >=3.7.0<=3.7.2 | |
Puppet Enterprise | >=3.8.0<=3.8.6 | |
Puppet Enterprise | >=2015.2.0<=2015.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-8470 is medium.
CVE-2015-8470 can allow remote attackers to capture the JSESSIONID cookie in an HTTPS session.
Puppet Enterprise versions 3.7.x, 3.8.x, and 2015.2.x are affected by CVE-2015-8470.
Yes, a fix is available for CVE-2015-8470. Please refer to the reference link for more information.
You can find more information about CVE-2015-8470 at the following reference link: <https://puppet.com/security/cve/CVE-2015-8470>