Vulnerabilities
Vulnerable Software
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
CVSS Score
9.8
EPSS Score
0.021
Published
2017-02-13
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-01-12
Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might allow local users to obtain sensitive information via unspecified vectors.
CVSS Score
4.7
EPSS Score
0.0
Published
2016-01-08


Contact Us

Shodan ® - All rights reserved