ID |
CVE-2015-4100
|
Sažetak |
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability." |
Reference |
|
CVSS |
Base: | 4.9 |
Impact: | 4.9 |
Exploitability: | 6.8 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
MEDIUM |
SINGLE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
PARTIAL |
NONE |
PARTIAL |
|
CVSS vektor |
AV:N/AC:M/Au:S/C:P/I:N/A:P |
Zadnje važnije ažuriranje |
24-01-2022 - 16:46 |
Objavljeno |
21-12-2017 - 15:29 |