← Back

Puppetlabs Mysql

puppetlabs-mysql

Vendor: Puppet • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Puppet
1Puppetlabs Mysql
Nov 21, 2024
Oct 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This conditi...Show more
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.Show less
2Fedoraproject
Puppet
2Fedora
Puppetlabs Mysql
Nov 21, 2024
Oct 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition...Show more
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.Show less
1Puppet
1Puppetlabs Mysql
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.