CVE-2015-5686: Puppet Enterprise
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.
Affected products
- Puppet Puppet Enterprise: from 3.0.0, before 2015.2.0 (fixed in 2015.2.0)
Published 2020-02-27. Last modified 2026-06-17.