CVE-2022-3275
9.8
CRITICAL
CVSS 3.1
EPSS 2.1%
Description
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
How to fix CVE-2022-3275
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/puppet-module-puppetlabs-apt—no fix listed
Is CVE-2022-3275 being exploited?
Low — EPSS is 2.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |