CVE-2010-2235
Summary
| CVE | CVE-2010-2235 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-09 20:00:00 UTC |
| Updated | 2023-02-13 04:20:00 UTC |
| Description | template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Michael Dehaan | Cobbler | 0.1.1.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.5.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.8.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.8.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.8-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.9-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.0-2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.3-4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.5-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.6-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.8-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.0-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3.1-2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.1.1.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.5.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.8.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.8.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.8-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.9-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.0-2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.3-4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.5-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.6-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.8-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.0-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3.1-2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support | REDHAT | www.redhat.com | |
| people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz | CONFIRM | people.fedoraproject.org | Patch |
| Red Hat Customer Portal | MISC | access.redhat.com | |
| access.redhat.com | CVE-2010-2235 | MISC | access.redhat.com | |
| Bug 607662 – CVE-2010-2235 RHN Satellite (cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file | CONFIRM | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.