CVE-2015-7224: Puppet Puppetlabs-MySQL
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.
Affected products
- Puppet Puppetlabs-MySQL: from 3.1.0, up to and including 3.6.0
Published 2017-12-21. Last modified 2026-06-17.