Description
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-5636 | Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session. |
References
| Link | Providers |
|---|---|
| https://puppet.com/security/cve/CVE-2015-5686/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T06:59:03.647Z
Reserved: 2015-07-27T00:00:00.000Z
Link: CVE-2015-5686
No data.
Status : Modified
Published: 2020-02-27T01:15:10.487
Modified: 2024-11-21T02:33:38.353
Link: CVE-2015-5686
No data.
OpenCVE Enrichment
No data.
EUVD