VDB
DEBIAN-CVE-2022-3276
DEBIAN-CVE-2022-3276
PUBLISHED
CVSS 8.800000190734863 HIGH
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | puppet-module-puppetlabs-mysql | 0, 15.0.0-1, 15.0.0-2 |
| Debian:13 | puppet-module-puppetlabs-mysql | 0, 0, 0 |
| Debian:11 | puppet-module-puppetlabs-mysql | 15.0.0-3, 8.1.0-6, 15.0.0-1 |
| Debian:14 | puppet-module-puppetlabs-mysql | 0, 0, 0 |
Timeline
- Oct 7, 2022 CVE Published
- Apr 28, 2026 CVE Updated