CVE-2016-2788

MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
References
Link Resource
https://puppet.com/security/cve/cve-2016-2788 Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:puppet:marionette_collective:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.7:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.8:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.6:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

Information

Published : 2017-02-13 10:59

Updated : 2022-01-24 08:46


NVD link : CVE-2016-2788

Mitre link : CVE-2016-2788


JSON object : View

CWE
CWE-284

Improper Access Control

Advertisement

dedicated server usa

Products Affected

puppet

  • marionette_collective
  • puppet_enterprise