Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18324
HistoryFeb 22, 2022 - 12:00 a.m.

Cobbler Command Injection Vulnerability (CNVD-2022-18324)

2022-02-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
20
cobbler
command injection
cnvd-2022-18324
network installation server
linux
vulnerability
templar.py
cheetah code
python modules

EPSS

0.001

Percentile

35.5%

Cobbler is a network installation server suite that is primarily used to quickly set up Linux network installations. A command injection vulnerability exists in versions of Cobbler prior to 3.3.1, stemming from the check_for_invalid_imports function in the templar.py file, which allows Cheetah code to import Python modules via the “#from MODULE import” substring to import Python modules. No detailed vulnerability details are available at this time.