VYPR

MCollective

by MCollective

CVEs (2)

  • CVE-2014-0175CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.02

    mcollective has a default password set at install

  • CVE-2016-2788CriFeb 13, 2017
    risk 0.64cvss 9.8epss 0.02

    MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.