Описание
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | Puppet Enterprise only |
| esm-infra-legacy/trusty | not-affected | Puppet Enterprise only |
| precise | not-affected | Puppet Enterprise only |
| trusty | not-affected | Puppet Enterprise only |
| trusty/esm | not-affected | Puppet Enterprise only |
| upstream | not-affected | Puppet Enterprise only |
| vivid | not-affected | Puppet Enterprise only |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct ...
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3