Total vulnerabilities in the database
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.
Software | From | Fixed in |
---|---|---|
puppet / puppet_enterprise | 3.0.0 | 2015.2.0 |