Description
The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-4806 | The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors. |
References
| Link | Providers |
|---|---|
| http://puppetlabs.com/security/cve/cve-2013-4962/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T01:11:25.432Z
Reserved: 2013-07-29T00:00:00.000Z
Link: CVE-2013-4962
No data.
Status : Deferred
Published: 2013-08-20T22:55:04.527
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-4962
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD