CVE-2022-3275
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
Affected (3)
Products: Puppet: Puppetlabs Mysql · Fedoraproject: Fedora
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.0.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 36 |
References (6)
Source: security@puppet.com
Source: security@puppet.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.