CVE-2013-2716: Puppet Enterprise

Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.

Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1.2.x or 2.0.x versions, which allows remote attackers to obtain console access via a crafted cookie.

Affected products

  • Puppet Puppet Enterprise: up to and including 2.7.2; version 2.0.0 only; version 2.5.1 only; version 2.5.2 only
  • Puppetlabs Puppet: version 1.0.0 only; version 1.1.0 only; version 1.2.0 only; version 2.5.0 only; version 2.6.0 only

Published 2013-04-10. Last modified 2026-06-16.