Previous versions of Puppet Enterprise included versions of MCollective that were vulnerable to remote code execution because of improper field validation in `mco ping` commands. Puppet Enterprise 3.8.6 and 2016.2.1 include updated versions of MCollective to fix this vulnerability.
Affected Software Versions:
Resolved in: