Cobbler vulnerable to arbitrary code execution
Critical severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Oct 10, 2023
Description
Published by the National Vulnerability Database
Jan 3, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jul 26, 2023
Last updated
Oct 10, 2023
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
References