Vulnerability identifier: #VU41958
Vulnerability risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-264
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Puppet Enterprise
Client/Desktop applications /
Software for system administration
Vendor: Puppet Labs
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Puppet Enterprise: 3.0.0 - 3.1.0
External links
https://puppetlabs.com/security/cve/cve-2013-4971
https://www.securitytracker.com/id/1029873
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.