HIGH 7.8 PyPI

Command Injection in Cobbler

GHSA-6cm4-gm85-972c · CVE-2021-45082 · PYSEC-2022-37

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An issue was discovered in Cobbler through 3.3.0. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

Ready to move

Start Securing

Free, no credit card | First findings in minutes