An issue was discovered in Cobbler through 3.3.0. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
| Score | Percentile |
|---|---|
| 0.04% | 12.84% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.8 | 3.1 | — |
|
| 8.5 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-6cm4-gm85-972c ↗ |
| CVE | CVE-2021-45082 ↗ |
| CWE id | Name |
|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | cobbler | < 3.3.1 | 3.3.1 | — |