VendorsPuppetmarionette_collectiveall versions
Vulnerabilities

Puppet Marionette Collective

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2016-2788
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
Published 2017-02-13 · Modified
9.8EPSS 0.023
CVE-2014-0175
mcollective has a default password set at install
Published 2019-12-13 · Modified
9.8EPSS 0.020
CVE-2014-3248
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.
Published 2014-11-16 · Modified
6.2EPSS 0.005