The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.
References
Configurations
Information
Published : 2014-10-26 18:55
Updated : 2014-10-28 18:17
NVD link : CVE-2011-4953
Mitre link : CVE-2011-4953
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
cobbler_project
- cobbler