Skip to content

Cobbler is vulnerable to code injection

High severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Feb 13, 2023

Package

pip cobbler (pip)

Affected versions

< 2.0.7

Patched versions

2.0.7

Description

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.

References

Published by the National Vulnerability Database Dec 9, 2010
Published to the GitHub Advisory Database May 17, 2022
Reviewed Feb 7, 2023
Last updated Feb 13, 2023

Severity

High

EPSS score

0.596%
(79th percentile)

Weaknesses

CVE ID

CVE-2010-2235

GHSA ID

GHSA-jhm7-38xj-pvm8

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.