CVE-2013-4963 PUBLISHED CVSS 6.800000190734863 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.

EPSS 0.12% · 30.3th percentile

Risk Scores

CVSS v2.0
6.800000190734863
EPSS Score
0.12%
30.3th percentile

Affected Products

VendorProductVersions
puppetpuppet_enterprise2.8.3, 0, 1.0
n/an/an/a

Timeline

References

Open in Interactive Console →