First published: Mon Aug 30 2021(Updated: )
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Enterprise | <2019.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27020 is a vulnerability in Puppet Enterprise that allows an attacker to execute malicious code by exploiting a lack of input sanitization during a CSV export.
CVE-2021-27020 has a severity rating of 8.8, which is considered high.
CVE-2021-27020 affects Puppet Enterprise versions up to and including 2019.8.6 by not properly sanitizing user input during a CSV export, introducing a security risk.
An attacker can exploit CVE-2021-27020 by inserting malicious code in user input during a CSV export, which can then be executed on the server.
Yes, an update to Puppet Enterprise version 2019.8.7 or later addresses the vulnerability and includes the necessary input sanitization.