CVE-2014-3225
Publication date 14 May 2014
Last updated 24 July 2024
Ubuntu priority
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.
Status
Package | Ubuntu Release | Status |
---|---|---|
cobbler | ||
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial |
Fixed 2.4.1-0ubuntu2+esm1
|
|
14.04 LTS trusty | Not in release | |
maas-provision | ||
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProNotes
jdstrand
maas-provision in 12.04 is a code copy of cobbler, but with reduced features and usage. Only the portions of maas-provision specifically used by maas will recieve official support maas-provision does not ship web_ui and is therefore not affected
References
Related Ubuntu Security Notices (USN)
- USN-6475-1
- Cobbler vulnerabilities
- 13 November 2023