CVE-2021-27021

EUVD-2021-13794
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
puppetpuppet
𝑥
< 6.23.0
puppetpuppet
7.7.0 ≤
𝑥
< 7.8.0
puppetpuppet_enterprise
𝑥
< 2019.8.7
puppetpuppet_enterprise
2021.0.0 ≤
𝑥
< 2021.2.0
puppetpuppetdb
𝑥
< 6.17.0
puppetpuppetdb
7.0.0 ≤
𝑥
< 7.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
puppetdb
bookworm
7.12.1-3
fixed
buster
no-dsa
sid
8.4.1-2
fixed
trixie
8.4.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
puppetdb
bionic
dne
focal
dne
groovy
dne
hirsute
dne
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
not-affected
noble
not-affected
trusty
dne
xenial
ignored