CVE-2022-0675

MEDIUM

Puppet Firewall <= 3.4.0 - Unmanaged Rule Persistence

Title source: llm
STIX 2.1

Description

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://puppet.com/security/cve/CVE-2022-0675

Scores

CVSS v3 5.6
EPSS 0.0088
EPSS Percentile 54.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-1289 CWE-20
Status published
Products (1)
puppet/firewall < 3.4.0
Published Mar 02, 2022
Tracked Since Feb 18, 2026