SUSE-SU-2021:3151-1
Dashboard / Vulnerabilities / SUSE-SU-2021:3151-1
SUSE-SU-2021:3151-1
Summary: Security update for cobbler
Details: This update for cobbler fixes the following issues: Security issues fixed: - CVE-2021-40323: Fixed an arbitrary file disclosure/Template Injection (bsc#1189458) - CVE-2021-40324: Fixed an arbitrary file write (bsc#1189458) - CVE-2021-40325: Fixed a problem with the token validation (bsc#1189458) - Please note that with these changes, a valid log data from Anamon (Red Hat Autoinstallation Process) uploaded to cobbler may be rejected
References: https://www.suse.com/support/update/announcement/2021/suse-su-20213151-1/, https://bugzilla.suse.com/1189458, https://www.suse.com/security/cve/CVE-2021-40323, https://www.suse.com/security/cve/CVE-2021-40324, https://www.suse.com/security/cve/CVE-2021-40325
Affected packages
Package
Name: cobbler
Purl: pkg:rpm/suse/cobbler&distro=SUSE%20Manager%20Server%20Module%204.1
Affected ranges
Type: ECOSYSTEM
Events:
