CVE-2013-4962 PUBLISHED CVSS 5.800000190734863 MEDIUM

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

EPSS 0.35% · 57.3th percentile

Risk Scores

CVSS v2.0
5.800000190734863
EPSS Score
0.35%
57.3th percentile

Affected Products

VendorProductVersions
n/an/an/a
puppetpuppet_enterprise0, 2.5.1, 2.5.2

Timeline

References

Open in Interactive Console →