Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vc9-4xpq-77vm

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cobbler Arbitrary File Read

A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.

Пакеты

Наименование

cobbler

pip
Затронутые версииВерсия исправления

<= 2.6.11-1

Отсутствует

EPSS

Процентиль: 53%
0.00305
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.

CVSS3: 6.1
nvd
больше 7 лет назад

A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.

CVSS3: 6.1
debian
больше 7 лет назад

A flaw was found in cobbler software component version 2.6.11-1. It su ...

EPSS

Процентиль: 53%
0.00305
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79