Vulnerabilities > Puppet > Mcollective > 0.4.10

DATE CVE VULNERABILITY TITLE RISK
2017-06-30 CVE-2017-2292 Deserialization of Untrusted Data vulnerability in Puppet Mcollective
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server.
network
low complexity
puppet CWE-502
7.5