CVE-2011-4953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/10/2014
Last modified:
12/04/2025

Description

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:* 2.2.1 (including)