CVE-2008-6954Code Injection in Project Cobbler

Severity
9.0CRITICALNVD
EPSS
1.6%
top 18.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 17

Description

The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

4
GHSA
Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability2022-05-17
OSV
Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability2022-05-17
GHSA
Cobbler is vulnerable to code injection2022-05-17
CVEList
CVE-2008-6954: The web interface (CobblerWeb) in Cobbler before 12009-08-12

📋Vendor Advisories

1
Red Hat
(cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file2010-10-18
CVE-2008-6954 — Code Injection in Project Cobbler | cvebase