CVE-2013-4964 PUBLISHED CVSS 5 MEDIUM

Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS 0.24% · 47.4th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
0.24%
47.4th percentile

Affected Products

VendorProductVersions
puppetpuppet_enterprise2.8.3, 0, 2.5.1
n/an/an/a

Timeline

References

Open in Interactive Console →