Описание
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.1 (включая)
Одно из
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_enterprise:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_enterprise:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_enterprise:3.1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.0025
Низкий
5 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
debian
больше 11 лет назад
Puppet Enterprise before 3.2.0 does not properly restrict access to no ...
github
больше 3 лет назад
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
EPSS
Процентиль: 48%
0.0025
Низкий
5 Medium
CVSS2
Дефекты
CWE-264