puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.
| Software | From | Fixed in |
|---|---|---|
| puppet / puppetlabs-mysql | 3.1.0 | 3.6.0.x |