CVE-2009-4261
published 2009-12-21CVE-2009-4261: Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.28%
86.9th percentile
Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors."
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ganeti | < ganeti 2.0.5-1 (bookworm) | ganeti 2.0.5-1 (bookworm) |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| roman_marxer | ganeti | — | — |
| spi-inc | ganeti | >= 0 < 2.0.5-1 | 2.0.5-1 |
| spi-inc | ganeti | >= 0 < 2.0.5-1 | 2.0.5-1 |
| spi-inc | ganeti | >= 0 < 2.0.5-1 | 2.0.5-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-4261: ganeti - Multiple directory traversal vulnerabilities in the iallocator framework in Gane...
vendor_debian·2009·CVSS 7.5
CVE-2009-4261 [HIGH] CVE-2009-4261: ganeti - Multiple directory traversal vulnerabilities in the iallocator framework in Gane...
Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors."
Scope: local
bookworm: resolved (fixed in 2.0.5-1)
bullseye: resolved (fixed in 2.0.5-1)
sid: resolved (fixed in 2.0.5-1)
trixie: resolved (fixed in 2.0.5-1)
GHSA
GHSA-h3gm-pcx4-7hmp: Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1
ghsa_unreviewed·2022-05-02
CVE-2009-4261 [HIGH] CWE-22 GHSA-h3gm-pcx4-7hmp: Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1
Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors."
OSV
CVE-2009-4261: Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1
osv·2009-12-21·CVSS 7.5
CVE-2009-4261 [HIGH] CVE-2009-4261: Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1
Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=NEWS%3Bh=34b46426eca82c351e0a478c71edb66b9bb4b228%3Bhp=7f916c59238503915e927377d887b93eef1f676c%3Bhb=e5823b7e2cd8a3c9037a10aa59823a45642ce29f%3Bhpb=f95c81bf21c177f7e6a2c53ea0613034326329bdhttp://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/constants.py%3Bh=81302575487a44ed192e61aa7b21888a215ef215%3Bhp=c353878ed83ce66d21c237da5e709dedd7b6f26b%3Bhb=0084657a21afb49c6f74498f27b97dfdbc42b383%3Bhpb=d24cb69273e4b03ffcd4e4768d95841b5570e264http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/utils.py%3Bh=bcd8e107bbc44ff94a4bc3dc405b5547719f001d%3Bhp=df2d18027e83b7783e146cbbe58f7efa92317980%3Bhb=f95c81bf21c177f7e6a2c53ea0613034326329bd%3Bhpb=4fe80ef2ed1cda3a6357274eccafe5c1f21a5283http://git.ganeti.org/?p=ganeti.git%3Ba=commit%3Bh=f95c81bf21c177f7e6a2c53ea0613034326329bdhttp://groups.google.com/group/ganeti/browse_thread/thread/cbce23d89103a8d2http://secunia.com/advisories/37849http://www.ocert.org/advisories/ocert-2009-019.htmlhttp://www.openwall.com/lists/oss-security/2009/12/17/5http://www.securityfocus.com/archive/1/508535/100/0/threadedhttp://www.vupen.com/english/advisories/2009/3599http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=NEWS%3Bh=34b46426eca82c351e0a478c71edb66b9bb4b228%3Bhp=7f916c59238503915e927377d887b93eef1f676c%3Bhb=e5823b7e2cd8a3c9037a10aa59823a45642ce29f%3Bhpb=f95c81bf21c177f7e6a2c53ea0613034326329bdhttp://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/constants.py%3Bh=81302575487a44ed192e61aa7b21888a215ef215%3Bhp=c353878ed83ce66d21c237da5e709dedd7b6f26b%3Bhb=0084657a21afb49c6f74498f27b97dfdbc42b383%3Bhpb=d24cb69273e4b03ffcd4e4768d95841b5570e264http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/utils.py%3Bh=bcd8e107bbc44ff94a4bc3dc405b5547719f001d%3Bhp=df2d18027e83b7783e146cbbe58f7efa92317980%3Bhb=f95c81bf21c177f7e6a2c53ea0613034326329bd%3Bhpb=4fe80ef2ed1cda3a6357274eccafe5c1f21a5283http://git.ganeti.org/?p=ganeti.git%3Ba=commit%3Bh=f95c81bf21c177f7e6a2c53ea0613034326329bdhttp://groups.google.com/group/ganeti/browse_thread/thread/cbce23d89103a8d2http://secunia.com/advisories/37849http://www.ocert.org/advisories/ocert-2009-019.htmlhttp://www.openwall.com/lists/oss-security/2009/12/17/5http://www.securityfocus.com/archive/1/508535/100/0/threadedhttp://www.vupen.com/english/advisories/2009/3599
2009-12-21
Published