CVE-2014-3225
Published May 14, 2014
Last updated 6 years ago
Overview
- Description
- Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cobblerd:cobbler:2.4.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77E45FEE-77FD-4E38-A437-530DB0FB0726" }, { "criteria": "cpe:2.3:a:cobblerd:cobbler:2.4.0:1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0875D8D3-9421-4E74-AC82-00F444971EFC" }, { "criteria": "cpe:2.3:a:cobblerd:cobbler:2.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A83D8CA5-9B9D-4BFF-8DBF-4EFD79AA9485" }, { "criteria": "cpe:2.3:a:cobblerd:cobbler:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B202661-286F-45BD-9402-BF744AD23521" }, { "criteria": "cpe:2.3:a:cobblerd:cobbler:2.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCAB8299-192E-45A3-96DA-A2D047A30639" }, { "criteria": "cpe:2.3:a:cobblerd:cobbler:2.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6C55580F-7FA7-445C-AC12-FC145C5EBF1E" }, { "criteria": "cpe:2.3:a:cobblerd:cobbler:2.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF231D52-CB23-4312-80E0-B4E3A0AB69DA" } ], "operator": "OR" } ] } ]