pkg:Debian/mcollective

6 total CVEsCRITICAL3

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2014-0175mcollective has a default password set at install
    from 0
  • CRITICAL9.8CVE-2016-2788MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relat…
    from 0, < 2.12.0+dfsg-1
  • CRITICAL9.0CVE-2017-2292Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code…
    from 0, < 2.12.0+dfsg-1
  • CVE-2014-3248facter, hiera, mcollective-client, and puppet affected by untrusted search path vulnerability
    from 0, < 2.5.2+dfsg-1
  • CVE-2014-3251The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new…
    from 0, < 2.6.0+dfsg-1
  • CVE-2014-0164openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective…
    from 0, < 1.2.1+dfsg-2