Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi cobbler Security Advisories

Loading...
High
GSA_kwCzR0hTQS1qaG03LTM4eGotcHZtOM4AAgFD
Cobbler is vulnerable to code injection
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
GSA_kwCzR0hTQS1nMzRjLW1nNm0teHZ4as4AAfoT
Cobbler subject to Command Injection
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS1ocGozLTVwNDYtZzg3d84AAeNk
Cobbler vulnerable to code injection via unsafe YAML loading
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
High
GSA_kwCzR0hTQS1wOHcyLWY0NHAtZm1jas4AAaur
Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS05Nmh3LXY1OTgtanZnaM4AAXi3
Cobbler vulnerable to arbitrary code execution
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 10.2
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS14Yzd3LWp2aHgtcDZxOc4AAWID
Cobbler Path Traversal vulnerability
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS1xOWc1LTk4cG0tdzZxN84AAVU1
Cobbler XSS Vulnerability
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 6.4
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS04Nzg3LTYzcHgtM20yM84AATHc
Cobbler has Exposed Dangerous Method or Function
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 10.2
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS1mODhxLTIyZzgtZnJjZ84AASjg
Cobbler Improper Validation of Security Tokens
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 10.2
Published: almost 2 years ago
Moderate
GSA_kwCzR0hTQS00dmM5LTR4cHEtNzd2bc4AARmW
Cobbler Arbitrary File Read
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 6.4
Published: almost 2 years ago
High
GSA_kwCzR0hTQS05ZnFyLXBxYzktZjdwas0_Ew
Cobbler Web Interface Lacks CSRF Protection
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 9.2
Published: about 2 years ago
High
GSA_kwCzR0hTQS1tY2c2LWgzNjItY21xNc0yIQ
Improper Authorization in cobbler
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 8.5
Published: about 2 years ago
High
GSA_kwCzR0hTQS01OTQ2LW1wdzUtcHF4eM0t4A
Incorrect Default Permissions in Cobbler
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 7.4
Published: about 2 years ago
High
GSA_kwCzR0hTQS02Y200LWdtODUtOTcyY80t2w
Command Injection in Cobbler
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 8.1
Published: about 2 years ago
High
GSA_kwCzR0hTQS1jcjNmLXIyNGotM2Nod80WIw
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 7.8
Published: over 2 years ago
High
GSA_kwCzR0hTQS1jcHFmLTNjM3ItYzlnMs0WIg
Cobbler before 3.3.0 allows log poisoning
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
High
GSA_kwCzR0hTQS00Y2ZyLWdqZngtZmozeM0WIQ
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
Ecosystems: pypi
Packages: cobbler
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 2 years ago
Statistics
Advisories: 17,583
Packages: 8,150
Repositories: 2
Ecosystems: 12
Filter by Package
tensorflow 432 tensorflow-cpu 387 tensorflow-gpu 384 django 80 apache-airflow 78 ansible 63 apache-superset 48 plone 42 rdiffweb 42 Pillow 41 salt 38 Plone 36 matrix-synapse 34 vyper 32 opencv-contrib-python 30 opencv-python 30 mlflow 30 Django 21 langchain 18 PaddlePaddle 17 cobbler 17 notebook 15 pillow 15 paddlepaddle 15 cryptography 15 modoboa 14 gradio 14 pyload-ng 13 pyftpdlib 13 nova 13 OctoPrint 12 neutron 12 keystone 12 vantage6 12 calibreweb 11 onionshare-cli 11 twisted 11 urllib3 11 glance 11 Flask-AppBuilder 10 aiohttp 10 ethyca-fides 9 zope 9 wagtail 9 opencv-contrib-python-headless 9 waitress 9 moin 9 opencv-python-headless 9 Zope 9 kiwitcms 9 numpy 8 label-studio 8 aubio 8 python-keystoneclient 7 matrix-sydent 7 pip 7 nautobot 7 scrapy 7 pysaml2 7 lief 7 jupyter-server 7 swift 7 tuf 6 lxml 6 graphite-web 6 ipython 6 Zope2 6 pgadmin4 6 apache-airflow-providers-apache-hive 6 web2py 6 mailman 6 sentry 6 inventree 6 mindsdb 6 Products.CMFPlone 5 whoogle-search 5 ckan 5 feedparser 5 bleach 5 trytond 5 python-gnupg 5 saleor 5 paramiko 5 roundup 5 horizon 5 pyspark 5 lmdb 5 requests 5 PyPDF2 4 transformers 4 FreeTAKServer-UI 4 markdown2 4 yt-dlp 4 httpie 4 oauthenticator 4 buildbot 4 Pygments 4 reportlab 4 jupyterhub 4 Jinja2 4 nltk 4 qutebrowser 4 GitPython 4 keylime 4 grpcio 4 grpc 4 starlette 4 ansible-core 4 datasette 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 aws-iot-device-sdk-v2 4 Flask-Security-Too 4 bottle 4 werkzeug 4 esphome 4 pretix 4 nvflare 4 omero-web 4 awsiotsdk 4 rsa 3 apache-libcloud 3 apache-iotdb 3 pyyaml 3 apache-airflow-providers-apache-spark 3 asyncua 3 io.grpc:grpc-protobuf 3 fava 3 sickrage 3 wger 3 flask 3 keyring 3 indico 3 protobuf 3 pandasai 3 pyarrow 3 mayan-edms 3 asyncssh 3 ray 3 ryu 3 tornado 3 streamlit 3 copyparty 3 Werkzeug 3 django-helpdesk 3 ecdsa 3 sanic 3 tripleo-heat-templates 3 ujson 3 Weblate 3 plone.supermodel 3 plone.app.dexterity 3 plone.app.theming 3 plone.app.event 3 ansible-runner 3 mitmproxy 3 slixmpp 3 clearml 3 docassemble.webapp 3 quokka 3 jwcrypto 3 torchserve 3 onnx 3 sqlparse 3 jupyterlab 3 poetry 3 localstack 3 mistune 3 openvpn-monitor 3 zenml 3 indy-node 3 aim 3 gerapy 3 bitlyshortener 3 pywasm3 3 cinder 3 Products.PluggableAuthService 3 barbican 3 Keystone 3 aws-encryption-sdk 2 fastapi 2 webargs 2 tripleo-ansible 2 Red-DiscordBot 2 pymatgen 2 scancodeio 2 dbt-core 2 langchain-experimental 2 apache-airflow-providers-apache-drill 2 in-toto 2 snowflake-connector-python 2 starkbank-ecdsa 2 aiohttp-session 2 djblets 2 aws-encryption-sdk-cli 2 apache-airflow-providers-cncf-kubernetes 2 apache-airflow-providers-apache-sqoop 2 distributed 2 embedchain 2 dtale 2 sosreport 2