UNKNOWN PyPI

Cobbler Path Traversal vulnerability

GHSA-xc7w-jvhx-p6q9 · CVE-2014-3225 · PYSEC-2026-797

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

Ready to move

Start Securing

Free, no credit card | First findings in minutes