The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.
References
Link | Resource |
---|---|
http://puppetlabs.com/security/cve/cve-2013-4962/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-08-20 15:55
Updated : 2019-07-10 11:10
NVD link : CVE-2013-4962
Mitre link : CVE-2013-4962
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
puppet
- puppet_enterprise