—
PYSEC-2022-177
Quick fix
PYSEC-2022-177 — cobbler: upgrade to the fixed version with the command below.
pip install --upgrade 'cobbler>=9044aa990a94752fa5bd5a24051adde099280bfa'Details
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/cobbler
Introduced in:
0Fixed in: 9044aa990a94752fa5bd5a24051adde099280bfaFix
pip install --upgrade 'cobbler>=9044aa990a94752fa5bd5a24051adde099280bfa'References
- https://huntr.dev/bounties/c458b868-63df-414e-af10-47e3745caa1d[WEB]
- https://github.com/cobbler/cobbler/commit/9044aa990a94752fa5bd5a24051adde099280bfa[FIX]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DYWYHWVVRUSPCV5SWBOSAMQJQLTSBTKY/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYSHMF6MEIITFAG7EJ3IQKVUN7MDV2XM/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D4KCNZYBQC2FM5SEEDRQZO4LRZ4ZECMG/[WEB]
- https://github.com/advisories/GHSA-mcg6-h362-cmq5[ADVISORY]