Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-45082 Details

Description

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')[email protected]

Affected Products

ProductVersions
cobbler project cobbler
< 3.3.1

CPE

  • cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
opensuse factory
All versions

CPE

  • cpe:2.3:a:opensuse:factory:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
opensuse backports
sle-15 sp3
sle-15 sp4

CPE

  • cpe:2.3:o:opensuse:backports:sle-15:sp3:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:backports:sle-15:sp4:*:*:*:*:*:*

Remediation

  • No remediation found in references.
suse linux enterprise server
11 sp3
12 -
15 sp2
15 sp3

CPE

  • cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:15:sp2:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:15:sp3:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
34
35
36

CPE

  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

9 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-45082
NVD Published Date:
Feb 19, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-45082 Details - Not Deferred