Executive brief
A vulnerability in the Puppet Enterprise web console allows attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can send them to a fake login page to steal credentials or perform phishing attacks. This affects organizations using Puppet Enterprise to manage their IT infrastructure.
Technical details
An open redirect vulnerability exists in the Console component of Puppet Enterprise due to improper validation of the 'redirect' parameter in the login URL. Attackers can bypass existing character filters by using a double forward slash (//) followed by an external domain. This flaw is an incomplete fix for a previous vulnerability (CVE-2015-6501). Successful exploitation requires a user to click a malicious link, which then redirects them to an attacker-controlled site after or during the authentication process, facilitating phishing or credential theft. The issue is resolved in Puppet Enterprise version 2016.4.0.
Affected products
- Puppet Puppet Enterprise 2015.x, 2016.x before 2016.4.0
Timeline
- 2016-08-23: disclosed: Vendor notified and acknowledged the report.
- 2016-10-17: patched: Public disclosure and fix released in version 2016.4.0.
- 2017-01-12: advisory: NVD advisory published.
References
- http://hyp3rlinx.altervista.org/advisories/PUPPET-AUTHENTICATION-REDIRECT.txt
- http://packetstormsecurity.com/files/139302/Puppet-Enterprise-Web-Interface-Open-Redirect.html
- http://www.securityfocus.com/archive/1/539618/100/0/threaded
- http://www.securityfocus.com/bid/93846
- https://puppet.com/security/cve/cve-2016-5715