PT-2014-2182 · Cobbler+1 · Cobbler+1

David

·

Publicado

2014-10-27

·

Atualizado

2024-06-15

·

CVE-2011-4953

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cobbler versions prior to 2.2.2
Description The issue allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe load function, as demonstrated using Puppet. This is due to a problem in the set mgmt parameters function in item.py.
Recommendations For versions prior to 2.2.2, update to version 2.2.2 or later to resolve the issue. As a temporary workaround, consider modifying the set mgmt parameters function to use yaml.safe load instead of yaml.load until a patch is available. Restrict access to the item.py module to minimize the risk of exploitation.

Correção

Code Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4953
GHSA-HPJ3-5P46-G87W
OPENSUSE-SU-2021:0046-1
OPENSUSE-SU-2021:0058-1
OPENSUSE-SU-2021_0046-1
OPENSUSE-SU-2024:10690-1
OPENSUSE-SU-2024:10897-1

Produtos afetados

Suse
Cobbler