CVE-2011-4953

EPSS 0.71%

Cobbler vulnerable to code injection via unsafe YAML loading

Published: 5/17/2022Modified: 12/7/2024

Description

The `set_mgmt_parameters` function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the `yaml.load` function instead of the `yaml.safe_load function`, as demonstrated using Puppet.

Affected packages (1)

References (6)