CVE-2021-27021
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.3%
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
nono source reports it
In short
PuppetDB has a vulnerability that lets users delete database tables without proper permission, escalating their privileges beyond what they should have.
Technical detail
A privilege escalation flaw in PuppetDB allows authenticated users to execute arbitrary SQL queries, including DROP TABLE commands, bypassing authorization controls on database operations.
Summary generated and translated by AI from the official description.
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
Affected products
n/a · Puppet DB