4.6
CVSSv2

CVE-2021-45082

Published: 19/02/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Cobbler prior to 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cobbler project cobbler

suse linux enterprise server 11

opensuse factory -

suse linux enterprise server 12

suse linux enterprise server 15

opensuse backports sle-15

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

An issue was discovered in Cobbler before 331 In the templarpy file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring (Only lines beginning with #import are blocked) ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Multiple vulnerabilities affecting cobbler <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Paolo Perego &lt;ppere ...