CVE-2013-4963: Puppet Enterprise

Medium severity, CVSS 6.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.

Affected products

  • Puppet Puppet Enterprise: up to and including 3.0.0; version 1.0 only; version 1.1 only; version 1.2.0 only; version 2.0.0 only; version 2.0.1 only; …

Published 2014-03-14. Last modified 2026-06-16.