CVE-2011-4953

EPSS 0.71%

Cobbler vulnerable to code injection via unsafe YAML loading

發布日:2022/5/17修改日:2024/12/7

描述

The `set_mgmt_parameters` function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the `yaml.load` function instead of the `yaml.safe_load function`, as demonstrated using Puppet.

受影響套件(1)

參考連結(6)