CVE-2013-4968: Puppet Enterprise
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
Affected products
- Puppet Puppet Enterprise: from 2.0.0, before 3.0.1 (fixed in 3.0.1)
Published 2019-12-11. Last modified 2026-06-16.