36 Total advisories
36 Vulnerabilities
0 Malware

Dependency scanning

Check whether cobbler is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.8
PyPI

CVE-2018-1000226

Cobbler Improper Validation of Security Tokens

CRITICAL 9.8
PyPI

CVE-2017-1000469

Cobbler vulnerable to arbitrary code execution

MEDIUM 6.1
PyPI

CVE-2018-1000225

Cobbler XSS Vulnerability

UNKNOWN
PyPI

CVE-2010-2235

Cobbler is vulnerable to code injection

UNKNOWN
PyPI

CVE-2012-2395

Cobbler subject to Command Injection

UNKNOWN
PyPI

CVE-2011-4953

Cobbler vulnerable to code injection via unsafe YAML loading

UNKNOWN
PyPI

CVE-2014-3225

Cobbler Path Traversal vulnerability

UNKNOWN
PyPI

CVE-2008-6954

Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability

UNKNOWN
PyPI

CVE-2008-6954

Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability

UNKNOWN
PyPI

CVE-2014-3225

Cobbler Path Traversal vulnerability

MEDIUM 6.1
PyPI

CVE-2018-1000225

Cobbler XSS Vulnerability

UNKNOWN
PyPI

CVE-2010-2235

Cobbler is vulnerable to code injection

UNKNOWN
PyPI

CVE-2011-4953

Cobbler vulnerable to code injection via unsafe YAML loading

UNKNOWN
PyPI

CVE-2012-2395

Cobbler subject to Command Injection

HIGH 8.8
PyPI

CVE-2011-4952

Cobbler Web Interface Lacks CSRF Protection

MEDIUM 6.1
PyPI

CVE-2016-9605

Cobbler Arbitrary File Read

HIGH 8.8
PyPI

CVE-2011-4952

Cobbler Web Interface Lacks CSRF Protection

MEDIUM 6.1
PyPI

CVE-2016-9605

Cobbler Arbitrary File Read

CRITICAL 9.8
PyPI

CVE-2024-47533

cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes

CRITICAL 9.8
PyPI

CVE-2018-10931

Cobbler has Exposed Dangerous Method or Function

CRITICAL 9.8
PyPI

CVE-2017-1000469

Cobbler vulnerable to arbitrary code execution

CRITICAL 9.8
PyPI

CVE-2024-47533

cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes

CRITICAL 9.8
PyPI

CVE-2018-10931

Cobbler has Exposed Dangerous Method or Function

CRITICAL 9.8
PyPI

CVE-2018-1000226

Cobbler Improper Validation of Security Tokens

UNKNOWN
PyPI

CVE-2021-45083

CVE-2021-45083

UNKNOWN
PyPI

CVE-2021-45082

CVE-2021-45082

UNKNOWN
PyPI

CVE-2022-0860

CVE-2022-0860

UNKNOWN
PyPI

CVE-2021-40325

CVE-2021-40325

UNKNOWN
PyPI

CVE-2021-40324

CVE-2021-40324

UNKNOWN
PyPI

CVE-2021-40323

CVE-2021-40323

HIGH 8.2
PyPI

CVE-2022-0860

Improper Authorization in cobbler

HIGH 7.1
PyPI

CVE-2021-45083

Incorrect Default Permissions in Cobbler

HIGH 7.5
PyPI

CVE-2021-40325

Cobbler before 3.3.0 allows authorization bypass for modification of settings.

HIGH 7.5
PyPI

CVE-2021-40324

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

CRITICAL 9.8
PyPI

CVE-2021-40323

Cobbler before 3.3.0 allows log poisoning

HIGH 7.8
PyPI

CVE-2021-45082

Command Injection in Cobbler

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes