CVE-2014-3225
14.05.2014, 00:55
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.
Vendor | Product | Version |
---|---|---|
cobblerd | cobbler | 2.4.0 |
cobblerd | cobbler | 2.4.0:1 |
cobblerd | cobbler | 2.4.1 |
cobblerd | cobbler | 2.4.2 |
cobblerd | cobbler | 2.4.3 |
cobblerd | cobbler | 2.4.4 |
cobblerd | cobbler | 2.6.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
cobbler |
| ||||||||||||||||||||||||||||||||||||||||||||
maas-provision |
|
References