CVE-2023-5309: Broken Session Management in Puppet Enterprise
Published Nov 7, 2023
·Updated
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
Affected Software
2 affected components
puppet Puppet Enterprise<2021.7.6
puppet Puppet Enterprise>=2023.0<2023.5.0
Event History
Nov 7, 2023
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5309?
CVE-2023-5309 is a vulnerability in Puppet Enterprise that results in broken session management for SAML implementations.
2
What is the severity of CVE-2023-5309?
The severity of CVE-2023-5309 is critical with a CVSS score of 9.8.
3
Which versions of Puppet Enterprise are affected by CVE-2023-5309?
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 are affected by CVE-2023-5309.
4
How can I fix the broken session management issue in Puppet Enterprise?
To fix the broken session management issue, update Puppet Enterprise to version 2021.7.6 or 2023.5.
5
Where can I find more information about CVE-2023-5309?
Additional information about CVE-2023-5309 can be found at https://www.puppet.com/security/cve/cve-2023-5309-broken-session-management-puppet-enterprise.