Marionette collective
This hub aggregates every CVE we track for Marionette collective, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
2
Critical
0
High
0
In CISA KEV
Severity distribution
CRITICAL2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Marionette collective.
- CVE-2014-0175mcollective has a default password set at install9.8
- CVE-2016-2788MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.9.8
- CVE-2014-3248Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2...6.2
Product normalization is registry-driven with AI assist and human review. How it works