CVE-2011-4953
Cobbler vulnerable to code injection via unsafe YAML loading
EPSS 2.2%
Description
The `set_mgmt_parameters` function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the `yaml.load` function instead of the `yaml.safe_load function`, as demonstrated using Puppet.
How to fix CVE-2011-4953
To remediate CVE-2011-4953, upgrade the affected package to a fixed version below.
- PyPI/cobbler—upgrade to 2.6.0 or later
- PyPI/cobbler—upgrade to 2.6.0 or later
Is CVE-2011-4953 being exploited?
Low — EPSS is 2.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.6.0
- from 0, < 2.6.0