CVE-2016-2788

MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
References
Link Resource
https://puppet.com/security/cve/cve-2016-2788 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:puppet:marionette_collective:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.6:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.7:*:*:*:*:*:*:*
cpe:2.3:a:puppet:marionette_collective:2.8.8:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

History

24 Jan 2022, 16:46

Type Values Removed Values Added
CPE cpe:2.3:a:puppet:puppet:*:*:*:*:enterprise:*:*:* cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

Information

Published : 2017-02-13 18:59

Updated : 2024-02-04 19:11


NVD link : CVE-2016-2788

Mitre link : CVE-2016-2788

CVE.ORG link : CVE-2016-2788


JSON object : View

Products Affected

puppet

  • puppet_enterprise
  • marionette_collective
CWE
CWE-284

Improper Access Control