Back

HIGH

(cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file

Published Dec 9, 2010

Description

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 9, 2010
Updated Aug 7, 2024
Reserved Jun 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 18, 2010
GHSA-JHM7-38XJ-PVM8