Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwq5-v5rc-g6r2

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."

EPSS

Процентиль: 55%
0.00327
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."

CVSS3: 6.1
nvd
около 6 лет назад

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."

CVSS3: 6.1
debian
около 6 лет назад

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct ...

EPSS

Процентиль: 55%
0.00327
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79