HIGH · 7.8

CVE-2021-45082

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring....

Vulnerability Description

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Cobbler ProjectCobbler< 3.3.1
OpensuseFactory-
OpensuseBackportssle-15
SuseLinux Enterprise Server11
FedoraprojectFedora34

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-45082?

CVE-2021-45082 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring....

How severe is CVE-2021-45082?

CVE-2021-45082 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-45082?

Check the references section above for vendor advisories and patch information. Affected products include: Cobbler Project Cobbler, Opensuse Factory, Opensuse Backports, Suse Linux Enterprise Server, Fedoraproject Fedora.