CVE Vulnerabilities

CVE-2021-27021

Published: Jul 20, 2021 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.9 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
Ubuntu
MEDIUM

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.

Affected Software

Name Vendor Start Version End Version
Puppet Puppet * 6.23.0 (excluding)
Puppet Puppet 7.7.0 (including) 7.8.0 (excluding)
Puppet_enterprise Puppet * 2019.8.7 (excluding)
Puppet_enterprise Puppet 2021.0.0 (including) 2021.2.0 (excluding)
Puppetdb Puppet * 6.17.0 (excluding)
Puppetdb Puppet 7.0.0 (including) 7.4.1 (excluding)
Puppetdb Ubuntu esm-apps/jammy *
Puppetdb Ubuntu impish *
Puppetdb Ubuntu jammy *
Puppetdb Ubuntu kinetic *
Puppetdb Ubuntu lunar *
Puppetdb Ubuntu trusty *
Puppetdb Ubuntu upstream *
Puppetdb Ubuntu xenial *

References