Description
The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4186 | The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet. |
Github GHSA |
GHSA-hpj3-5p46-g87w | Cobbler vulnerable to code injection via unsafe YAML loading |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T00:23:38.624Z
Reserved: 2011-12-23T00:00:00.000Z
Link: CVE-2011-4953
No data.
Status : Modified
Published: 2014-10-27T01:55:24.107
Modified: 2026-05-06T22:30:45.220
Link: CVE-2011-4953
OpenCVE Enrichment
No data.
EUVD
Github GHSA