PT-2017-8261 · Puppet · Mcollective

Publicado

2017-02-13

·

Atualizado

2022-01-24

·

CVE-2016-2788

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MCollective versions 2.7.0 through 2.8.8 MCollective version 2.8.x before 2.8.9
Description The issue allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
Recommendations For MCollective versions 2.7.0 through 2.8.8, update to version 2.8.9 or later. For MCollective version 2.8.x before 2.8.9, update to version 2.8.9 or later.

Correção

RCE

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-2788

Produtos afetados

Mcollective