CVE-2017-2293
Summary
| CVE | CVE-2017-2293 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-01 22:29:00 UTC |
| Updated | 2022-01-24 16:46:00 UTC |
| Description | Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these actions. Customers who rely on this functionality can change this policy. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Puppet | Puppet | All | All | All | All |
| Application | Puppet | Puppet | 2016.5.1 | All | All | All |
| Application | Puppet | Puppet | 2016.5.2 | All | All | All |
| Application | Puppet | Puppet | 2017.1.0 | All | All | All |
| Application | Puppet | Puppet | 2017.1.1 | All | All | All |
| Application | Puppet | Puppet | All | All | All | All |
| Application | Puppet | Puppet | 2016.5.1 | All | All | All |
| Application | Puppet | Puppet | 2016.5.2 | All | All | All |
| Application | Puppet | Puppet | 2017.1.0 | All | All | All |
| Application | Puppet | Puppet | 2017.1.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | All | All | All | All |
| Application | Puppet | Puppet Enterprise | 2016.5.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2016.5.2 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2017.1.0 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2017.1.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-2293 - MCollective Server Allows Installing Arbitrary Packages On Agents | Puppet.com | CONFIRM | puppet.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.