CVE-2010-2235: Code Injection
A code injection flaw was found in the way Cobbler processed templates for kickstart files. A remote authenticated user, that has the Configuration Administrator role privilege, could use this flaw to create a specially-crafted kickstart template file containing embedded Python code, that could, when processed by the Cheetah template processing engine, execute arbitrary code with the privileges of the privileged system user (root) on the Red Hat Network Satellite Server host.
References: [1] https://fedorahosted.org/cobbler/wiki/KickstartTemplating
Acknowledgements:
Red Hat would like to thank Doug Knight of University of Alaska for reporting this issue.
Other sources
templateapi.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2235?
CVE-2010-2235 is classified as a moderate severity vulnerability.
How do I fix CVE-2010-2235?
To fix CVE-2010-2235, upgrade Cobbler to version 1.6.6 or later.
Who is affected by CVE-2010-2235?
CVE-2010-2235 affects remote authenticated users with Configuration Administrator role privilege on vulnerable Cobbler versions.
What type of vulnerability is CVE-2010-2235?
CVE-2010-2235 is a code injection vulnerability that allows execution of arbitrary embedded Python code.
Which versions of Cobbler are affected by CVE-2010-2235?
Affected versions of Cobbler include 1.0.2, 1.2.0, 1.2.2, 1.2.3, 1.2.5, 1.2.6, 1.2.8, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, and numerous others up to 2.0.4.