CVE-2012-5158
14.03.2014, 16:55
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.Enginsight
Vendor | Product | Version |
---|---|---|
puppet | puppet_enterprise | 𝑥 ≤ 2.6.0 |
puppet | puppet_enterprise | 2.0.0 |
puppet | puppet_enterprise | 2.5.1 |
puppet | puppet_enterprise | 2.5.2 |
puppetlabs | puppet | 2.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration