CVE-2016-2788: Critical severity Puppet Marionette Collective vulnerability
Published Feb 13, 2017
·Updated
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
Affected Software
12 affected components
Puppet Marionette Collective=2.7.0
Puppet Marionette Collective=2.8.0
Puppet Marionette Collective=2.8.1
Puppet Marionette Collective=2.8.2
Puppet Marionette Collective=2.8.3
Puppet Marionette Collective=2.8.4
Puppet Marionette Collective=2.8.5
Puppet Marionette Collective=2.8.6
Puppet Marionette Collective=2.8.7
Puppet Marionette Collective=2.8.8
Puppet Puppet Enterprise>=3.8.0<3.8.6
Puppet Puppet Enterprise>=2016.2.0<2016.2.1
Event History
Feb 13, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-2788?
CVE-2016-2788 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-2788?
To fix CVE-2016-2788, upgrade MCollective to version 2.8.9 or later.
3
Which versions of MCollective are affected by CVE-2016-2788?
CVE-2016-2788 affects MCollective versions 2.7.0 and 2.8.0 through 2.8.8.
4
Can CVE-2016-2788 be exploited remotely?
Yes, CVE-2016-2788 allows remote attackers to execute arbitrary code via exploitation of the mco ping command.
5
Is there any workaround for CVE-2016-2788?
Currently, there are no known effective workarounds for CVE-2016-2788, so upgrading is recommended.