Description
template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.
Published: 2010-12-09
Score: 8.5 High
EPSS: 1.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-4375 template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.
Github GHSA Github GHSA GHSA-jhm7-38xj-pvm8 Cobbler is vulnerable to code injection
History

No history.

Subscriptions

Michael Dehaan Cobbler
Redhat Network Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T02:25:07.514Z

Reserved: 2010-06-09T00:00:00.000Z

Link: CVE-2010-2235

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-12-09T20:00:17.147

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-2235

cve-icon Redhat

Severity : Important

Publid Date: 2010-10-18T00:00:00Z

Links: CVE-2010-2235 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses