Puppetlabs-mysql Command Injection
Published Oct 7, 2022
8.8
HIGHCVSS 3.1
EPSS 1.68%
Description
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<13.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Puppet | Puppetlabs-Mysql | n/a |
|
- < 13.0.0
No data.
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
puppet-mysql-0:5.2.2-0.20180216012143.a5497b2.el7ost
Fixed · RHSA-2022:7238
Red Hat OpenStack Platform 13.0 - ELS
puppet-mysql-0:5.2.2-0.20180216012143.a5497b2.el7ost
Fixed · RHSA-2022:7238
Red Hat OpenStack Platform 16.1
puppet-mysql-0:10.4.1-2.20221019195006.95f9b98.el8ost
Fixed · RHSA-2022:7238
Red Hat OpenStack Platform 16.2
puppet-mysql-0:10.4.1-2.20221019195006.95f9b98.el8ost
Fixed · RHSA-2022:7238
Red Hat OpenStack Platform 17.0
puppet-mysql-0:10.6.1-0.20220614215045.937d044.el9ost
Fixed · RHSA-2022:7238
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | puppet-mysql-0:5.2.2-0.20180216012143.a5497b2.el7ost | Fixed | RHSA-2022:7238 |
| Red Hat OpenStack Platform 13.0 - ELS | puppet-mysql-0:5.2.2-0.20180216012143.a5497b2.el7ost | Fixed | RHSA-2022:7238 |
| Red Hat OpenStack Platform 16.1 | puppet-mysql-0:10.4.1-2.20221019195006.95f9b98.el8ost | Fixed | RHSA-2022:7238 |
| Red Hat OpenStack Platform 16.2 | puppet-mysql-0:10.4.1-2.20221019195006.95f9b98.el8ost | Fixed | RHSA-2022:7238 |
| Red Hat OpenStack Platform 17.0 | puppet-mysql-0:10.6.1-0.20220614215045.937d044.el9ost | Fixed | RHSA-2022:7238 |
No package ranges for this CVE.
Remediation
Red Hat statement
This condition is rare in most deployments of Puppet and Puppet Enterprise.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-3276 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2132541 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42673 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3276
- https://puppet.com/security/cve/CVE-2022-3276 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3276
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3276 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2132541 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42673 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3276 | ||
| https://puppet.com/security/cve/CVE-2022-3276 | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3276 |
Change history (0)
No recorded changes yet.