Vulnerability Name: | CVE-2013-4962 (CCN-86488) | ||||||||
Assigned: | 2013-08-15 | ||||||||
Published: | 2013-08-15 | ||||||||
Updated: | 2019-07-10 | ||||||||
Summary: | The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-4962 Source: CCN Type: Puppet Labs Web Site CVE-2013-4962 (Lack of Reauthentication for Sensitive Transactions) Source: CONFIRM Type: Vendor Advisory http://puppetlabs.com/security/cve/cve-2013-4962/ Source: CCN Type: SA54552 Puppet Enterprise Multiple Vulnerabilities Source: XF Type: UNKNOWN puppet-cve20134962-sec-bypass(86488) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4962 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |