Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4953

Опубликовано: 28 сент. 2011
Источник: redhat
CVSS2: 7.1

Описание

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

Отчет

This issue did not affect the version of cobbler as shipped with Red Hat Network Satellite Server 5.4 as it did not include the upstream commit d7b30b5fca5097c544ca37ade8c945a3106b1896 that introduced this flaw.

Дополнительная информация

Статус:

Important
Дефект:
CWE-96
https://bugzilla.redhat.com/show_bug.cgi?id=811920cobbler: Privilege escalation by processing of crafted management parameters

7.1 High

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

nvd
почти 12 лет назад

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

debian
почти 12 лет назад

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 al ...

github
около 4 лет назад

Cobbler vulnerable to code injection via unsafe YAML loading

suse-cvrf
больше 5 лет назад

Security update for cobbler

7.1 High

CVSS2