Vulnerabilities > Cobbler Project > Cobbler > 2.2.1

DATE CVE VULNERABILITY TITLE RISK
2022-03-11 CVE-2022-0860 Improper Authorization vulnerability in multiple products
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
network
low complexity
cobbler-project fedoraproject CWE-285
critical
9.1
2022-02-20 CVE-2021-45081 Cleartext Transmission of Sensitive Information vulnerability in Cobbler Project Cobbler
An issue was discovered in Cobbler through 3.3.1.
network
high complexity
cobbler-project CWE-319
5.9
2021-10-04 CVE-2021-40323 Code Injection vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
network
low complexity
cobbler-project CWE-94
7.5
2021-10-04 CVE-2021-40324 Unrestricted Upload of File with Dangerous Type vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
network
low complexity
cobbler-project CWE-434
5.0
2021-10-04 CVE-2021-40325 Unspecified vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
network
low complexity
cobbler-project
7.5
2018-01-03 CVE-2017-1000469 Improper Input Validation vulnerability in Cobbler Project Cobbler 2.2.1
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
network
low complexity
cobbler-project CWE-20
critical
10.0
2014-10-27 CVE-2011-4953 Improper Input Validation vulnerability in Cobbler Project Cobbler 2.2.1
The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.
6.8