CVE-2017-1000469: Input Validation
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1000469?
CVE-2017-1000469 is a command injection vulnerability in the "add repo" component of Cobbler version up to 2.8.2.
How does CVE-2017-1000469 affect Cobbler?
CVE-2017-1000469 allows an attacker to execute arbitrary code as the root user in Cobbler version up to 2.8.2.
What is the severity of CVE-2017-1000469?
CVE-2017-1000469 has a severity rating of 9.8 (Critical).
How can I fix CVE-2017-1000469 in Cobbler?
To fix CVE-2017-1000469, it is recommended to upgrade Cobbler to version 3.0.0 or higher.
Where can I find more information about CVE-2017-1000469?
You can find more information about CVE-2017-1000469 from the following references: 1) https://nvd.nist.gov/vuln/detail/CVE-2017-1000469, 2) https://github.com/cobbler/cobbler/issues/1845, 3) https://github.com/cobbler/cobbler/commit/4b20397425a5d42a2d8927233654f4d7435bd4c2.