CVE-2021-27020: High severity puppet enterprise vulnerability
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27020?
CVE-2021-27020 is a vulnerability in Puppet Enterprise that allows an attacker to execute malicious code by exploiting a lack of input sanitization during a CSV export.
What is the severity of CVE-2021-27020?
CVE-2021-27020 has a severity rating of 8.8, which is considered high.
How does CVE-2021-27020 affect Puppet Enterprise?
CVE-2021-27020 affects Puppet Enterprise versions up to and including 2019.8.6 by not properly sanitizing user input during a CSV export, introducing a security risk.
How can an attacker exploit CVE-2021-27020?
An attacker can exploit CVE-2021-27020 by inserting malicious code in user input during a CSV export, which can then be executed on the server.
Is there a fix for CVE-2021-27020?
Yes, an update to Puppet Enterprise version 2019.8.7 or later addresses the vulnerability and includes the necessary input sanitization.