QID 996731
Date Published: 2024-01-17
QID 996731: Python (Pip) Security Update for cobbler (GHSA-hpj3-5p46-g87w)
The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hpj3-5p46-g87w for updates and patch information.
Vendor References
- GHSA-hpj3-5p46-g87w -
github.com/advisories/GHSA-hpj3-5p46-g87w
CVEs related to QID 996731
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hpj3-5p46-g87w | cobbler |
|