UBUNTU-CVE-2017-2292
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-2292
Summary:
Details: Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-supplied MCollective plugins, but there is a chance that third-party plugins could rely on this insecure behavior.
References: https://ubuntu.com/security/CVE-2017-2292, https://puppet.com/security/cve/cve-2017-2292, https://github.com/puppetlabs/marionette-collective/commit/e0e741889f5adeb8f75387037106b0d28a9099b0, https://www.cve.org/CVERecord?id=CVE-2017-2292
Affected packages
Package
Name: mcollective
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
