6.5
CVSSv2

CVE-2021-27021

Published: 20/07/2021 Updated: 24/01/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A flaw exists in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet

puppet puppet enterprise

puppet puppetdb

Vendor Advisories

Debian Bug report logs - #990419 CVE-2021-27021 Package: puppetdb; Maintainer for puppetdb is Puppet Package Maintainers <pkg-puppet-devel@listsaliothdebianorg>; Source for puppetdb is src:puppetdb (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 28 Jun 2021 17:54:02 UTC Severity: ...
No description is available for this CVE ...
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query This has been resolved in Puppet DB 6170, 741, Platform 623, 770 and Puppet Enterprise 20212, 201987 ...