Skip to content

CVE-2012-5158

Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0016 (0.2%)
Percentile: 36.0%
EPSS: 2026-05-06

Affects

puppet:puppet_enterprisepuppetlabs:puppet

Technical description

Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.

Published: 3/14/2014, 4:55:04 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam