Security Advisory

CVE-2013-4967

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-08-20 22:00:00
Last updated 2024-09-17 00:11:37
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes.