Lucene search

K
cvelistPuppetCVELIST:CVE-2022-3275
HistoryOct 07, 2022 - 12:00 a.m.

CVE-2022-3275 Puppetlabs-apt Command Injection

2022-10-0700:00:00
CWE-78
puppet
www.cve.org
10
puppetlabs-apt
command injection
cve-2022-3275
vulnerability
unsantized input
puppet enterprise

CVSS3

8.4

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.004

Percentile

73.2%

Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.

CNA Affected

[
  {
    "vendor": "Puppet",
    "product": "puppetlabs-apt",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "9.0.0",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.4

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.004

Percentile

73.2%