NA

CVE-2022-3275

Published: 07/10/2022 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppetlabs-mysql

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1023625 puppet-module-puppetlabs-apt: CVE-2022-3275 Package: src:puppet-module-puppetlabs-apt; Maintainer for src:puppet-module-puppetlabs-apt is Puppet Package Maintainers <pkg-puppet-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 7 Nov 2022 19:3 ...
DescriptionThe MITRE CVE dictionary describes this issue as: Command injection is possible in the puppetlabs-apt module prior to version 900 A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module This condition is rare in most deployments of Puppet and Puppet Enterprise ...