CVE-2022-3276

Published Oct 7, 2022

Last updated 6 months ago

Overview

Description
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
Source
security@puppet.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@puppet.com
CWE-78
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations