CVE-2013-4971
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0025 (0.3%)
Percentile: 48.2%
EPSS: 2026-05-06
Affects
puppet:puppet_enterpriseTechnical description
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
Published: 3/9/2014, 1:16:56 PM
Last modified: 5/6/2026, 10:30:45 PM