First published: Wed Aug 12 2009(Updated: )
The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Michael Dehaan Cobbler | =1.0.2 | |
Michael Dehaan Cobbler | =1.2.0 | |
Michael Dehaan Cobbler | =0.2.3 | |
Michael Dehaan Cobbler | =1.2.2 | |
Michael Dehaan Cobbler | =0.2.7 | |
Michael Dehaan Cobbler | =0.3.5 | |
Michael Dehaan Cobbler | =0.3.0 | |
Michael Dehaan Cobbler | =1.2.6 | |
Michael Dehaan Cobbler | =0.4.0 | |
Michael Dehaan Cobbler | =1.2.3 | |
Michael Dehaan Cobbler | =0.4.3 | |
Michael Dehaan Cobbler | =0.8.1 | |
Michael Dehaan Cobbler | =0.2.5 | |
Michael Dehaan Cobbler | =0.8.3 | |
Michael Dehaan Cobbler | =1.0.2-1 | |
Michael Dehaan Cobbler | =0.3.7 | |
Michael Dehaan Cobbler | <=1.2.8 | |
Michael Dehaan Cobbler | =0.6.4 | |
Michael Dehaan Cobbler | =0.4.6 | |
Michael Dehaan Cobbler | =0.2.1 | |
Michael Dehaan Cobbler | =0.4.7 | |
Michael Dehaan Cobbler | =0.6.5 | |
Michael Dehaan Cobbler | =0.6.1 | |
Michael Dehaan Cobbler | =1.2.5 | |
Michael Dehaan Cobbler | =0.1.1.7 | |
Michael Dehaan Cobbler | =0.3.9 | |
Michael Dehaan Cobbler | =0.4.2 | |
Michael Dehaan Cobbler | =1.0.3-1 | |
Michael Dehaan Cobbler | =1.0.0 | |
Michael Dehaan Cobbler | =0.5.0 | |
Michael Dehaan Cobbler | =0.6.0 | |
Michael Dehaan Cobbler | =0.3.4 | |
Michael Dehaan Cobbler | =0.2.8 | |
Michael Dehaan Cobbler | =1.2.7 | |
Michael Dehaan Cobbler | =0.2.2 | |
Michael Dehaan Cobbler | =0.4.8 | |
Michael Dehaan Cobbler | =0.6.3 | |
Michael Dehaan Cobbler | =0.3.1 | |
Michael Dehaan Cobbler | =0.2.9 | |
Michael Dehaan Cobbler | =0.3.3 | |
Michael Dehaan Cobbler | =0.4.5 | |
Michael Dehaan Cobbler | =0.3.6 | |
pip/cobbler | <1.2.9 | 1.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6954 has a medium severity rating due to its ability to execute arbitrary Python code by remote authenticated users.
To fix CVE-2008-6954, upgrade Cobbler to version 1.2.9 or later.
CVE-2008-6954 affects Cobbler versions prior to 1.2.9, including 1.0.2, 1.2.0, 1.2.6, and other earlier releases.
Users of Cobbler versions prior to 1.2.9 who have remote authenticated access are affected by CVE-2008-6954.
CVE-2008-6954 can be exploited by editing a Cheetah kickstart template in the CobblerWeb interface to import arbitrary Python modules.