CVE-2015-7331: Medium severity Puppetlabs Mcollective-puppet-agent Puppet vulnerability
Published Jan 30, 2017
·Updated
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.
Affected Software
1 affected component
Puppetlabs Mcollective-puppet-agent Puppet<=1.11.0
Event History
Jan 30, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-7331?
CVE-2015-7331 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2015-7331?
To fix CVE-2015-7331, upgrade the mcollective-puppet-agent plugin to version 1.11.1 or later.
3
What software is affected by CVE-2015-7331?
CVE-2015-7331 affects mcollective-puppet-agent versions prior to 1.11.1.
4
What type of vulnerability is CVE-2015-7331?
CVE-2015-7331 is a remote code execution vulnerability.
5
What conditions are needed to exploit CVE-2015-7331?
Exploitation of CVE-2015-7331 requires access to the mcollective-puppet-agent server with the exploit vector involving the --server argument.