QID 998089

QID 998089: Python (Pip) Security Update for cobbler (GHSA-xc7w-jvhx-p6q9)

Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Github security advisory GHSA-xc7w-jvhx-p6q9 for updates and patch information.
    Vendor References

    CVEs related to QID 998089

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xc7w-jvhx-p6q9 cobbler URL Logo github.com/advisories/GHSA-xc7w-jvhx-p6q9