CVE-2012-2395: High severity cobbler vulnerability
Incomplete blacklist vulnerability in actionpower.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the powersystem method in the xmlrpc API.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2395?
CVE-2012-2395 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2012-2395?
To fix CVE-2012-2395, upgrade Cobbler to version 2.2.1 or later, where the vulnerability is patched.
What type of vulnerability is CVE-2012-2395?
CVE-2012-2395 is an incomplete blacklist vulnerability that allows remote attackers to execute arbitrary commands.
What affected software does CVE-2012-2395 impact?
CVE-2012-2395 specifically impacts Cobbler version 2.2.0.
How can CVE-2012-2395 be exploited?
CVE-2012-2395 can be exploited by attackers who manipulate the username or password fields in the power_system method of the XML-RPC API.