First published: Sat Jun 16 2012(Updated: )
Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Michael Dehaan Cobbler | =2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2395 is classified as a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2012-2395, upgrade Cobbler to version 2.2.1 or later, where the vulnerability is patched.
CVE-2012-2395 is an incomplete blacklist vulnerability that allows remote attackers to execute arbitrary commands.
CVE-2012-2395 specifically impacts Cobbler version 2.2.0.
CVE-2012-2395 can be exploited by attackers who manipulate the username or password fields in the power_system method of the XML-RPC API.