CVE-2012-5158
14.03.2014, 16:55
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| puppet | puppet_enterprise | 𝑥 ≤ 2.6.0 |
| puppet | puppet_enterprise | 2.0.0 |
| puppet | puppet_enterprise | 2.5.1 |
| puppet | puppet_enterprise | 2.5.2 |
| puppetlabs | puppet | 2.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration