CVE-2022-3276
8.8
HIGH
CVSS 3.1
EPSS 1.6%
Description
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
How to fix CVE-2022-3276
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/puppet-module-puppetlabs-mysql—no fix listed
Is CVE-2022-3276 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |