First published: Wed Jan 03 2018(Updated: )
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/cobbler | <=2.8.2 | 3.0.0 |
Cobbler Project Cobbler | <=2.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000469 is a command injection vulnerability in the "add repo" component of Cobbler version up to 2.8.2.
CVE-2017-1000469 allows an attacker to execute arbitrary code as the root user in Cobbler version up to 2.8.2.
CVE-2017-1000469 has a severity rating of 9.8 (Critical).
To fix CVE-2017-1000469, it is recommended to upgrade Cobbler to version 3.0.0 or higher.
You can find more information about CVE-2017-1000469 from the following references: 1) https://nvd.nist.gov/vuln/detail/CVE-2017-1000469, 2) https://github.com/cobbler/cobbler/issues/1845, 3) https://github.com/cobbler/cobbler/commit/4b20397425a5d42a2d8927233654f4d7435bd4c2.