{"id":"CVE-2016-2788","details":"MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.","modified":"2026-07-08T05:48:27.034890504Z","published":"2017-02-13T18:59:00.457Z","database_specific":{"unresolved_ranges":[{"vendor_product":"puppet:puppet_enterprise","cpes":["cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.8.0"},{"fixed":"3.8.6"},{"introduced":"2016.2.0"},{"fixed":"2016.2.1"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"https://puppet.com/security/cve/cve-2016-2788"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/puppetlabs/marionette-collective","events":[{"introduced":"07cb2f2eacd9c14c063a781e9febc09db566938a"},{"last_affected":"1d427e2632abe360f8a7f41d8ccc6628a2c43e48"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:puppet:marionette_collective:2.7.0:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.0:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.1:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.2:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.3:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.4:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.5:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.6:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.7:*:*:*:*:*:*:*","cpe:2.3:a:puppet:marionette_collective:2.8.8:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"},{"introduced":"2.8.0"},{"last_affected":"2.8.0"},{"introduced":"2.8.1"},{"last_affected":"2.8.1"},{"introduced":"2.8.2"},{"last_affected":"2.8.2"},{"introduced":"2.8.3"},{"last_affected":"2.8.3"},{"introduced":"2.8.4"},{"last_affected":"2.8.4"},{"introduced":"2.8.5"},{"last_affected":"2.8.5"},{"introduced":"2.8.6"},{"last_affected":"2.8.6"},{"introduced":"2.8.7"},{"last_affected":"2.8.7"},{"introduced":"2.8.8"},{"last_affected":"2.8.8"}]}}],"versions":["2.7.0","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.8.7","2.8.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2788.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}