CVE-2013-4961: Puppet Enterprise
Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
Affected products
- Puppet Puppet Enterprise: up to and including 3.0.0; version 2.5.1 only; version 2.5.2 only; version 2.8.0 only; version 2.8.1 only; version 2.8.2 only; …
Published 2013-08-20. Last modified 2026-06-16.