« Volver al listado

CVE-2021-27019

Estado: ModificadaMedia (4.3)—

PuppetDB logging included potentially sensitive system information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27019",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@puppet.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "PuppetDB, Puppet Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "Affects PuppetDB 6.x prior to 6.16.1, PuppetDB 7.x prior to 7.3.1, Puppet Enterprise prior to 2019.8.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-08-30T18:15:08.570",
  "references": [
    {
      "url": "https://puppet.com/security/cve/CVE-2021-27019",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@puppet.com"
    },
    {
      "url": "https://puppet.com/security/cve/CVE-2021-27019",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-532"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PuppetDB logging included potentially sensitive system information."
    },
    {
      "lang": "es",
      "value": "El registro de PuppetDB incluía información potencialmente confidencial del sistema."
    }
  ],
  "lastModified": "2026-06-17T03:44:08.363",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2F6078A-A6F8-4850-BCF8-6483D6131861",
              "versionEndExcluding": "2019.8.6"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppetdb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2625208D-728B-4601-BA11-83EA54E1358E",
              "versionEndExcluding": "6.16.1",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppetdb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF0E1B3C-5F3E-49BC-B8DE-5B3AAC457B29",
              "versionEndExcluding": "7.3.1",
              "versionStartIncluding": "7.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@puppet.com"
}