CVE-2015-7224: Critical severity puppet labs mysql vulnerability
Published Dec 21, 2017
·Updated
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysqluser' user parameter contains a host with a netmask.
Affected Software
1 affected component
Puppet puppetlabs-mysql>=3.1.0<=3.6.0
Event History
Dec 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is CVE-2015-7224?
CVE-2015-7224 is a vulnerability in puppetlabs-mysql that allows remote attackers to bypass authentication.
2
How does CVE-2015-7224 work?
CVE-2015-7224 works by leveraging the creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.
3
What is the severity of CVE-2015-7224?
CVE-2015-7224 has a severity rating of 9.8 (critical).
4
How do I fix CVE-2015-7224?
To fix CVE-2015-7224, update puppetlabs-mysql to a version between 3.1.0 and 3.6.0.
5
Where can I find more information about CVE-2015-7224?
You can find more information about CVE-2015-7224 at the following link: https://puppet.com/security/cve/CVE-2015-7224