QID 997203

Date Published: 2024-02-12

QID 997203: Python (Pip) Security Update for cobbler (GHSA-p8w2-f44p-fmcj)

The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code with the root privileges in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Refer to Github security advisory GHSA-p8w2-f44p-fmcj for updates and patch information.
    Vendor References

    CVEs related to QID 997203

    Software Advisories
    Advisory ID Software Component Link
    GHSA-p8w2-f44p-fmcj cobbler URL Logo github.com/advisories/GHSA-p8w2-f44p-fmcj