Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cobbler 命令注入漏洞
Vulnerability Description
Cobbler是一款网络安装服务器套件,它主要用于快速建立Linux网络安装环境。 Cobbler 3.3.1之前版本存在安全漏洞,该漏洞源于templar.py文件里函数check_for_invalid_imports可以允许Cheetah代码通过“#from MODULE import”子字符串导入Python模块。
CVSS Information
N/A
Vulnerability Type
N/A