CVE-2021-45082

HIGH

Cobbler < 3.3.1 - Remote Code Execution via Cheetah Template Import Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

References (5)

Core 5
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/cobbler/cobbler/releases
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.suse.com/show_bug.cgi?id=1193678

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (10)
cobbler_project/cobbler < 3.3.1
fedoraproject/fedora 34
fedoraproject/fedora 35
fedoraproject/fedora 36
opensuse/backports sle-15 sp3 (2 CPE variants)
opensuse/factory
pypi/cobbler 0 - 3.3.1PyPI
suse/linux_enterprise_server 11 sp3
suse/linux_enterprise_server 12
suse/linux_enterprise_server 15 sp2 (2 CPE variants)
Published Feb 19, 2022
Tracked Since Feb 18, 2026