CVE-2014-0175
Published Dec 13, 2019mcollective has a default password set at install
Vendor/product archive
3 CVEs tagged to puppet / marionette_collective — 2 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
mcollective has a default password set at install
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mc…