CRITICAL
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask
Published Dec 21, 2017
9.8
CRITICALCVSS 3.0
EPSS 1.68%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.