« Volver al listado

CVE-2021-27021

Estado: ModificadaAlta (8.8)—

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27021",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@puppet.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Puppet DB",
          "versions": [
            {
              "status": "affected",
              "version": "All prior versions before Puppet DB 6.17.0, 7.4.1, Puppet Platform 6.23, 7.8.0 and PE 2021.2, 2019.8.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-20T11:15:11.630",
  "references": [
    {
      "url": "https://puppet.com/security/cve/cve-2021-27021/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@puppet.com"
    },
    {
      "url": "https://puppet.com/security/cve/cve-2021-27021/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@puppet.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1027"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query."
    },
    {
      "lang": "es",
      "value": "Se ha detectado un fallo en Puppet DB, este fallo resulta en una escalada de privilegios que permite al usuario eliminar tablas por medio de una consulta SQL"
    }
  ],
  "lastModified": "2026-06-17T03:44:08.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "113DE1D4-9D3F-4174-A430-9C51F4B2A86D",
              "versionEndExcluding": "6.23.0"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21324515-6AA9-4B82-92A6-CC002711B6C8",
              "versionEndExcluding": "7.8.0",
              "versionStartIncluding": "7.7.0"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "818DA61A-C405-48A0-ADC4-A0D9982C5CC7",
              "versionEndExcluding": "2019.8.7"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE812749-F357-4994-B04E-0C58B35485BA",
              "versionEndExcluding": "2021.2.0",
              "versionStartIncluding": "2021.0.0"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppetdb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C25190E0-8E19-41DD-949E-CD5C3F5F678D",
              "versionEndExcluding": "6.17.0"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppetdb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16D55C13-8C3D-4696-BF47-CBA82DCE14B7",
              "versionEndExcluding": "7.4.1",
              "versionStartIncluding": "7.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@puppet.com"
}