Junglewise Threat Intelligence

CVE-2015-7331: Puppet mcollective-puppet-agent remote code execution via --server argument

CVE-2015-7331 · Severity: medium · CVSS 6.6 · Published 2017-01-30

Executive brief

A vulnerability in the Puppet MCollective Puppet Agent plugin could allow an attacker to execute unauthorized commands on managed servers. This plugin is used to orchestrate and manage Puppet agents across an infrastructure. If exploited, an attacker could gain control over systems, potentially leading to data theft or service disruption.

Technical details

A remote code execution vulnerability exists in the mcollective-puppet-agent plugin for Puppet prior to version 1.11.1. The flaw is rooted in the handling of the '--server' argument, which can be manipulated to execute arbitrary commands. While the attack vector is network-based, successful exploitation typically requires high privileges and occurs under complex conditions (AC:H). An attacker with sufficient permissions to trigger agent runs could leverage this to execute code with the privileges of the MCollective daemon. The issue was addressed in version 1.11.1 of the plugin.

Affected products

  • Puppet mcollective-puppet-agent before 1.11.1

Timeline

  • 2015-09-16: disclosed: CVE reserved date
  • 2017-01-30: advisory: NVD publication date

References