Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade cobbler
to version 3.3.1 or higher.
cobbler is a network install server.
Affected versions of this package are vulnerable to Improper Input Validation due to improper sanitization of the run_triggers
function in the modules/installation/pre_log.py
module, which allows some user controller inputs to be appended in the /var/log/cobbler/install.log
log file, exploiting this vulnerability might cause log file pollution.