Vulnerability Name: | CVE-2013-4964 (CCN-86487) | ||||||||
Assigned: | 2013-08-15 | ||||||||
Published: | 2013-08-15 | ||||||||
Updated: | 2019-07-10 | ||||||||
Summary: | Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-4964 Source: CCN Type: Puppet Labs Web Site CVE-2013-4964 (Session Cookies Not Set With Secure Flag) Source: CONFIRM Type: Vendor Advisory http://puppetlabs.com/security/cve/cve-2013-4964/ Source: CCN Type: SA54552 Puppet Enterprise Multiple Vulnerabilities Source: XF Type: UNKNOWN puppet-cve20134964-weak-security(86487) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4964 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |