Vulnerability Name: | CVE-2021-45082 (CCN-219984) | ||||||||||||||||||||
Assigned: | 2021-12-16 | ||||||||||||||||||||
Published: | 2022-02-18 | ||||||||||||||||||||
Updated: | 2022-04-08 | ||||||||||||||||||||
Summary: | An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.) | ||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-77 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-45082 Source: MISC Type: Exploit, Issue Tracking, Patch, Third Party Advisory https://bugzilla.suse.com/show_bug.cgi?id=1193678 Source: XF Type: UNKNOWN cobbler-cve202145082-code-exec(219984) Source: CCN Type: Cobbler GIT Repository Security: Fix incomplete template sanitization Source: MISC Type: Release Notes, Third Party Advisory https://github.com/cobbler/cobbler/releases Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-0649006be6 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-0c6402a6a3 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-f1510aa454 Source: CCN Type: oss-sec Mailing List, Fri, 18 Feb 2022 13:26:29 +0100 Multiple vulnerabilities affecting cobbler | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |