Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1532468 - (CVE-2017-1000469) CVE-2017-1000469 cobbler: Command injection in the "add repo" component allows for remote code execution
CVE-2017-1000469 cobbler: Command injection in the "add repo" component allow...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20171019,repo...
: Security
Depends On: 1532469 1532470 1533708 1533709
Blocks: 1532471
  Show dependency treegraph
 
Reported: 2018-01-08 21:51 EST by Sam Fowler
Modified: 2018-01-30 10:46 EST (History)
13 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sam Fowler 2018-01-08 21:51:45 EST
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "Mirror" field of the "Adding a Repo" form. A remote user could exploit this to execute arbitrary code as root.

References:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-1000469
https://github.com/cobbler/cobbler/issues/1845
Comment 1 Sam Fowler 2018-01-08 21:52:26 EST
Created cobbler tracking bugs for this issue:

Affects: epel-all [bug 1532469]
Affects: fedora-all [bug 1532470]
Comment 3 Kurt Seifried 2018-01-11 20:41:26 EST
Statement:

Red Hat Satellite 5 is now in Production 3 Phase of the support and maintenance life cycle. The cobbler API has a user associated with it however the password is a randomly generated  64 character string, making the API inaccessible. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Note You need to log in before you can comment on or make changes to this bug.