CVE-2018-6510: XSS Vulnerability in Puppet Enterprise Console
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrator. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Puppet Enterprise Console (Puppet Enterprise Orchestrator)to a version that resolves this vulnerability.Fixed in 2017.3.6
Event History
Frequently Asked Questions
What is CVE-2018-6510?
CVE-2018-6510 is a cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise.
How does CVE-2018-6510 affect Puppet Enterprise Console?
CVE-2018-6510 allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrator.
What versions of Puppet Enterprise are affected by CVE-2018-6510?
Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.
What is the severity of CVE-2018-6510?
CVE-2018-6510 has a severity rating of medium with a CVSS score of 5.4.
How can I fix CVE-2018-6510?
To fix CVE-2018-6510, upgrade to Puppet Enterprise 2017.3.6 or later.