CVE-2015-5686: Puppet Enterprise

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

Affected products

  • Puppet Puppet Enterprise: from 3.0.0, before 2015.2.0 (fixed in 2015.2.0)

Published 2020-02-27. Last modified 2026-06-17.