Information disclosure in Puppet Enterprise - CVE-2013-4959

 

Information disclosure in Puppet Enterprise - CVE-2013-4959

Published: August 21, 2013 / Updated: August 10, 2020


Vulnerability identifier: #VU42647
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4959
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.


Affected software

Puppet Enterprise

How to mitigate CVE-2013-4959

Install update from vendor's website.


External References

Related Security Bulletins