CVE-2021-45082
HIGHCobbler < 3.3.1 - Remote Code Execution via Cheetah Template Import Bypass
Title source: llmDescription
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
References (5)
Core 5
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/cobbler/cobbler/releases
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.suse.com/show_bug.cgi?id=1193678
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z5CSXQE7Q4TVDQJKFYBO4XDH3BZ7BLAR/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEJN7CPW6YCHBFQPFZKGA6AVA6T5NPIW/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCXMOUW4DH4DYWIJN44SMSU6R3CZDZBE/
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
13.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (10)
cobbler_project/cobbler
< 3.3.1
fedoraproject/fedora
34
fedoraproject/fedora
35
fedoraproject/fedora
36
opensuse/backports
sle-15 sp3 (2 CPE variants)
opensuse/factory
pypi/cobbler
0 - 3.3.1PyPI
suse/linux_enterprise_server
11 sp3
suse/linux_enterprise_server
12
suse/linux_enterprise_server
15 sp2 (2 CPE variants)
Published
Feb 19, 2022
Tracked Since
Feb 18, 2026