CVE-2021-27021

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
puppetCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
puppetpuppet
𝑥
< 6.23.0
puppetpuppet
7.7.0 ≤
𝑥
< 7.8.0
puppetpuppet_enterprise
𝑥
< 2019.8.7
puppetpuppet_enterprise
2021.0.0 ≤
𝑥
< 2021.2.0
puppetpuppetdb
𝑥
< 6.17.0
puppetpuppetdb
7.0.0 ≤
𝑥
< 7.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
puppetdb
bookworm
7.12.1-3
fixed
buster
no-dsa
sid
8.4.1-2
fixed
trixie
8.4.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
puppetdb
noble
not-affected
mantic
not-affected
lunar
ignored
kinetic
ignored
jammy
needed
impish
ignored
hirsute
dne
groovy
dne
focal
dne
bionic
dne
xenial
ignored
trusty
dne