{"id":"GHSA-p8w2-f44p-fmcj","summary":"Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability","details":"The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code with the root privileges in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.","aliases":["CVE-2008-6954","PYSEC-2026-795"],"modified":"2026-07-07T11:56:26.193239554Z","published":"2022-05-17T02:10:02Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-02-09T18:39:18Z","nvd_published_at":"2009-08-12T10:30:00Z","cwe_ids":["CWE-94"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6954"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46625"},{"type":"PACKAGE","url":"https://github.com/cobbler/cobbler"},{"type":"WEB","url":"https://web.archive.org/web/20111227125913/http://secunia.com/advisories/32804"},{"type":"WEB","url":"https://web.archive.org/web/20111227151912/http://secunia.com/advisories/32737"},{"type":"WEB","url":"https://web.archive.org/web/20200228143518/http://www.securityfocus.com/bid/32317"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00462.html"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00485.html"},{"type":"WEB","url":"http://freshmeat.net/projects/cobbler/releases/288374"}],"affected":[{"package":{"name":"cobbler","ecosystem":"PyPI","purl":"pkg:pypi/cobbler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9"}]}],"versions":["0.6.3-2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p8w2-f44p-fmcj/GHSA-p8w2-f44p-fmcj.json"}}],"schema_version":"1.9.0"}