HIGH8.8
PYSEC-2026-624
Cobbler Web Interface Lacks CSRF Protection
Quick fix
PYSEC-2026-624 — cobbler: upgrade to the fixed version with the command below.
pip install --upgrade 'cobbler>=2.6.0'Details
cobbler: Web interface lacks CSRF protection when using Django framework
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2011-4952[ADVISORY]
- https://github.com/cobbler/cobbler/commit/18eb1c06779b37d89dfb2962a08236dd1bab24a6[WEB]
- https://github.com/cobbler/cobbler/commit/4bee30b4086a8d845bea5d39d6f2cba1f4a396aa[WEB]
- https://access.redhat.com/security/cve/cve-2011-4952[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4952[WEB]
- https://github.com/cobbler/cobbler[PACKAGE]
- https://security-tracker.debian.org/tracker/CVE-2011-4952[WEB]
- http://www.openwall.com/lists/oss-security/2012/04/12/10[WEB]
- https://pypi.org/project/cobbler[PACKAGE]
- https://github.com/advisories/GHSA-9fqr-pqc9-f7pj[ADVISORY]