Vulnerability Details CVE-2016-5715
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6501.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.5%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.8
Products affected by CVE-2016-5715
-
cpe:2.3:a:puppet:puppet_enterprise:2015.2.0
-
cpe:2.3:a:puppet:puppet_enterprise:2015.2.1
-
cpe:2.3:a:puppet:puppet_enterprise:2015.2.2
-
cpe:2.3:a:puppet:puppet_enterprise:2015.2.3
-
cpe:2.3:a:puppet:puppet_enterprise:2015.3.0
-
cpe:2.3:a:puppet:puppet_enterprise:2015.3.1
-
cpe:2.3:a:puppet:puppet_enterprise:2015.3.2
-
cpe:2.3:a:puppet:puppet_enterprise:2015.3.3
-
cpe:2.3:a:puppet:puppet_enterprise:2016.1.1
-
cpe:2.3:a:puppet:puppet_enterprise:2016.1.2
-
cpe:2.3:a:puppet:puppet_enterprise:2016.2.0
-
cpe:2.3:a:puppet:puppet_enterprise:2016.2.1
-
cpe:2.3:a:puppet:puppet_enterprise:2016.4.0