Improper Input Validation Affecting cobbler package, versions [,3.3.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-COBBLER-2419282
  • published9 Mar 2022
  • disclosed8 Mar 2022
  • creditSchoolGuy

Introduced: 8 Mar 2022

CVE NOT AVAILABLE CWE-20  (opens in a new tab)

How to fix?

Upgrade cobbler to version 3.3.1 or higher.

Overview

cobbler is a network install server.

Affected versions of this package are vulnerable to Improper Input Validation due to improper sanitization of the run_triggers function in the modules/installation/pre_log.py module, which allows some user controller inputs to be appended in the /var/log/cobbler/install.log log file, exploiting this vulnerability might cause log file pollution.

CVSS Scores

version 3.1