A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
References
Link | Resource |
---|---|
https://puppet.com/security/cve/cve-2021-27021/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-07-20 04:15
Updated : 2022-01-24 08:46
NVD link : CVE-2021-27021
Mitre link : CVE-2021-27021
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
puppet
- puppetdb
- puppet_enterprise
- puppet