Back

HIGH

Puppetlabs-mysql Command Injection

Published Oct 7, 2022

Description

Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.

Affected products

Remediation

Red Hat statement

This condition is rare in most deployments of Puppet and Puppet Enterprise.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner puppet
Published Oct 7, 2022
Updated Aug 3, 2024
Reserved Sep 22, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 4, 2022
ENISA EUVD
Assigner puppet
Published Oct 7, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-42673