CVE-2010-2235
Summary
| CVE | CVE-2010-2235 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-09 20:00:17 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Michael Dehaan | Cobbler | 0.1.1.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.2.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.3.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.4.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.5.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.6.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.8.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 0.8.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.0.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.7 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.8-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.9 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.2.9-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.3.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.0-2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.4.3-4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.2-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.3-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.4 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.5 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.5-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.6 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.6-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.8 | All | All | All |
| Application | Michael Dehaan | Cobbler | 1.6.8-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.0 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.0-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.1-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3.1 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.3.1-2 | All | All | All |
| Application | Michael Dehaan | Cobbler | 2.0.4-1 | All | All | All |
| Application | Michael Dehaan | Cobbler | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 607662 – CVE-2010-2235 RHN Satellite (cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz | af854a3a-2127-422b-91ae-364da2661108 | people.fedoraproject.org | Patch |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| access.redhat.com | CVE-2010-2235 | MITRE | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.