CVE-2014-3225 PUBLISHED

Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

EPSS 6.11% · 90.7th percentile

Risk Scores

EPSS Score
6.11%
90.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTScobbler0, 2.4.1-0ubuntu2

Timeline

References

Open in Interactive Console →