CVE-2018-6511: XSS Vulnerability in Puppet Enterprise Console
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Enterprise Console. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Puppet Enterprise Console (Puppet Enterprise)to a version that resolves this vulnerability.Fixed in 2017.3.6 - Configuration
Upgrade Puppet Enterprise Console to Puppet Enterprise 2017.3.6 to address the cross-site scripting (XSS) vulnerability; affected versions are 2017.3.x prior to 2017.3.6.
Puppet Enterprise Console XSS injection via Console when using the Puppet Enterprise Console = fixed by upgrading to 2017.3.6
Event History
Frequently Asked Questions
What is CVE-2018-6511 vulnerability?
CVE-2018-6511 is a cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise that allows a user to inject scripts into the Puppet Enterprise Console.
How does CVE-2018-6511 affect Puppet Enterprise?
CVE-2018-6511 affects Puppet Enterprise versions 2017.3.x prior to 2017.3.6.
What is the severity of CVE-2018-6511?
The severity of CVE-2018-6511 is medium, with a severity value of 5.4.
How can I fix the CVE-2018-6511 vulnerability in Puppet Enterprise?
To fix the CVE-2018-6511 vulnerability in Puppet Enterprise, update to version 2017.3.6 or later.
Where can I find more information about CVE-2018-6511?
More information about CVE-2018-6511 can be found at https://puppet.com/security/cve/CVE-2018-6511.