Skip to content

CVE-2013-4971

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0025 (0.3%)
Percentile: 48.2%
EPSS: 2026-05-06

Affects

puppet:puppet_enterprise

Technical description

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

Published: 3/9/2014, 1:16:56 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam