RSS   Podatności dla 'Mcollective-puppet-agent'   RSS

2017-03-03
 
CVE-2017-2290

CWE-732
 

 
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.

 
2017-01-30
 
CVE-2015-7331

 

 
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.

 

 >>> Vendor: Puppetlabs 15 Produkty
Puppet
Puppet enterprise users
Puppet enterprise
Puppet dashboard
Mcollective
Facter
Hiera
Marionette-collective
Puppet server
Stdlib
Rabbitmq
Puppetlabs-rabbitmq
Puppet agent
Mcollective-puppet-agent
Mcollective-sshkey-security


Copyright 2024, cxsecurity.com

 

Back to Top