Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45082

Опубликовано: 18 фев. 2022
Источник: redhat
CVSS3: 7.8

Описание

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

A flaw was found in cobbler. The vulnerability occurs due to incomplete template sanitization and leads to code injection. This flaw allows an attacker to interact and inject malicious codes and gain access to the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8rhn-tools:1.0/cobblerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2056388cobbler: incomplete template sanitization

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

CVSS3: 7.8
nvd
почти 4 года назад

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

CVSS3: 7.8
debian
почти 4 года назад

An issue was discovered in Cobbler before 3.3.1. In the templar.py fil ...

CVSS3: 7.8
github
почти 4 года назад

Command Injection in Cobbler

7.8 High

CVSS3