MEDIUM
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
Published Dec 11, 2019
6.1
MEDIUMCVSS 3.1
EPSS 0.82%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.