Mcollective
This hub aggregates every CVE we track for Mcollective, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
2
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM2CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 4 most recently published vulnerabilities affecting Mcollective.
- CVE-2014-0175mcollective has a default password set at install9.8
- CVE-2017-2292Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML....9.0
- CVE-2017-2298The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to a...6.5
- CVE-2014-3251The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which al...4.4
Product normalization is registry-driven with AI assist and human review. How it works