CVE-2010-2235
high
CVSS v3
—
CVSS v2
8.5
VIR risk
8.5
Description
Cobbler is vulnerable to code injection
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | cobbler | <2.0.7 | 2.0.7 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| michael_dehaan | cobbler | {"endIncluding":"2.0.4"} | |
| michael_dehaan | cobbler | 0.1.1.7 | |
| michael_dehaan | cobbler | 0.2.1 | |
| michael_dehaan | cobbler | 0.2.2 | |
| michael_dehaan | cobbler | 0.2.3 | |
| michael_dehaan | cobbler | 0.2.5 | |
| michael_dehaan | cobbler | 0.2.7 | |
| michael_dehaan | cobbler | 0.2.8 | |
| michael_dehaan | cobbler | 0.2.9 | |
| michael_dehaan | cobbler | 0.3.0 | |
| michael_dehaan | cobbler | 0.3.1 | |
| michael_dehaan | cobbler | 0.3.3 | |
| michael_dehaan | cobbler | 0.3.4 | |
| michael_dehaan | cobbler | 0.3.5 | |
| michael_dehaan | cobbler | 0.3.6 | |
| michael_dehaan | cobbler | 0.3.7 | |
| michael_dehaan | cobbler | 0.3.9 | |
| michael_dehaan | cobbler | 0.4.0 | |
| michael_dehaan | cobbler | 0.4.2 | |
| michael_dehaan | cobbler | 0.4.3 | |
| michael_dehaan | cobbler | 0.4.5 | |
| michael_dehaan | cobbler | 0.4.6 | |
| michael_dehaan | cobbler | 0.4.7 | |
| michael_dehaan | cobbler | 0.4.8 | |
| michael_dehaan | cobbler | 0.5.0 | |
| michael_dehaan | cobbler | 0.6.0 | |
| michael_dehaan | cobbler | 0.6.1 | |
| michael_dehaan | cobbler | 0.6.3 | |
| michael_dehaan | cobbler | 0.6.4 | |
| michael_dehaan | cobbler | 0.6.5 | |
| michael_dehaan | cobbler | 0.8.1 | |
| michael_dehaan | cobbler | 0.8.3 | |
| michael_dehaan | cobbler | 1.0.0 | |
| michael_dehaan | cobbler | 1.0.2 | |
| michael_dehaan | cobbler | 1.0.2-1 | |
| michael_dehaan | cobbler | 1.0.3-1 | |
| michael_dehaan | cobbler | 1.2.0 | |
| michael_dehaan | cobbler | 1.2.2 | |
| michael_dehaan | cobbler | 1.2.3 | |
| michael_dehaan | cobbler | 1.2.5 | |
| michael_dehaan | cobbler | 1.2.6 | |
| michael_dehaan | cobbler | 1.2.7 | |
| michael_dehaan | cobbler | 1.2.8 | |
| michael_dehaan | cobbler | 1.2.8-1 | |
| michael_dehaan | cobbler | 1.2.9 | |
| michael_dehaan | cobbler | 1.2.9-1 | |
| michael_dehaan | cobbler | 1.3.1 | |
| michael_dehaan | cobbler | 1.3.1-1 | |
| michael_dehaan | cobbler | 1.3.3 | |
| michael_dehaan | cobbler | 1.3.3-1 | |
| michael_dehaan | cobbler | 1.3.4 | |
| michael_dehaan | cobbler | 1.3.4-1 | |
| michael_dehaan | cobbler | 1.4.0 | |
| michael_dehaan | cobbler | 1.4.0-2 | |
| michael_dehaan | cobbler | 1.4.1 | |
| michael_dehaan | cobbler | 1.4.1-1 | |
| michael_dehaan | cobbler | 1.4.2 | |
| michael_dehaan | cobbler | 1.4.2-1 | |
| michael_dehaan | cobbler | 1.4.3 | |
| michael_dehaan | cobbler | 1.4.3-4 | |
| michael_dehaan | cobbler | 1.6.1 | |
| michael_dehaan | cobbler | 1.6.1-1 | |
| michael_dehaan | cobbler | 1.6.2 | |
| michael_dehaan | cobbler | 1.6.2-1 | |
| michael_dehaan | cobbler | 1.6.3 | |
| michael_dehaan | cobbler | 1.6.3-1 | |
| michael_dehaan | cobbler | 1.6.4 | |
| michael_dehaan | cobbler | 1.6.4-1 | |
| michael_dehaan | cobbler | 1.6.5 | |
| michael_dehaan | cobbler | 1.6.5-1 | |
| michael_dehaan | cobbler | 1.6.6 | |
| michael_dehaan | cobbler | 1.6.6-1 | |
| michael_dehaan | cobbler | 1.6.8 | |
| michael_dehaan | cobbler | 1.6.8-1 | |
| michael_dehaan | cobbler | 2.0.0 | |
| michael_dehaan | cobbler | 2.0.0-1 | |
| michael_dehaan | cobbler | 2.0.1 | |
| michael_dehaan | cobbler | 2.0.1-1 | |
| michael_dehaan | cobbler | 2.0.3 | |
| michael_dehaan | cobbler | 2.0.3.1 | |
| michael_dehaan | cobbler | 2.0.3.1-2 | |
| michael_dehaan | cobbler | 2.0.4-1 | |
References
- http://people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz
- http://www.redhat.com/support/errata/RHSA-2010-0775.html
- https://bugzilla.redhat.com/show_bug.cgi?id=607662
- https://nvd.nist.gov/vuln/detail/CVE-2010-2235
- https://access.redhat.com/errata/RHSA-2010:0775
- https://access.redhat.com/security/cve/CVE-2010-2235
- https://github.com/cobbler/cobbler
- https://people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz
- https://www.redhat.com/support/errata/RHSA-2010-0775.html
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.