Описание
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
Ссылки
- ExploitMitigationThird Party Advisory
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.2 (включая)
cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.0095
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 8 лет назад
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
CVSS3: 8.8
redhat
больше 8 лет назад
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
CVSS3: 9.8
debian
около 8 лет назад
Cobbler version up to 2.8.2 is vulnerable to a command injection vulne ...
EPSS
Процентиль: 76%
0.0095
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-20