PT-2021-6608 · Puppet+1 · Puppetdb+1
Published
2021-07-20
·
Updated
2024-01-23
·
CVE-2021-27021
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Puppet DB (affected versions not specified)
Description
A flaw in Puppet DB results in an escalation of privileges, allowing a user to delete tables via an SQL query. This issue is related to a lack of protection measures for the SQL query structure, which can be exploited by a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Puppetdb