CVE-2016-9605 PUBLISHED CVSS 6.099999904632568 MEDIUM

A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.

EPSS 0.30% · 53.6th percentile

Risk Scores

CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.30%
53.6th percentile

Affected Products

VendorProductVersions
The cobbler Projectcobbler2.6.11-1
PyPIcobbler0
cobbler_projectcobbler2.6.11-1

Timeline

References

Open in Interactive Console →