CVE-2021-45082

Severity
7.8HIGH
EPSS
0.0%
top 86.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateNov 13

Description

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

PyPIcobbler< 3.3.1
Ubuntucobbler< 2.4.1-0ubuntu2+esm1
NVDopensuse/backportssle-15

Also affects: Fedora 34, 35, 36

Patches

🔴Vulnerability Details

5
OSV
cobbler vulnerabilities2023-11-13
GHSA
Command Injection in Cobbler2022-02-20
OSV
Command Injection in Cobbler2022-02-20
OSV
CVE-2021-45082: An issue was discovered in Cobbler before 32022-02-19
CVEList
CVE-2021-45082: An issue was discovered in Cobbler before 32022-02-18

📋Vendor Advisories

2
Ubuntu
Cobbler vulnerabilities2023-11-13
Red Hat
cobbler: incomplete template sanitization2022-02-18