![]() |
VOOZH | about |
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| cobbler (Ubuntu) |
Invalid
|
High
|
Robie Basak | ||
| Oneiric |
Invalid
|
High
|
Robie Basak | ||
| Precise |
Invalid
|
High
|
Robie Basak | ||
While cobbler makes use of the django web-framework, it does not make use of the built in csrf protection, leaving the web interface vulnerable to csrf attacks.
Note: I installed cobbler as a result of installing ubuntu-orchestra. (cobbler version: 2.1.0+git20110602-0ubuntu25).
| description: | updated |
| visibility: | private β public |
| Changed in cobbler (Ubuntu): | |
| importance: | Undecided β High |
| Changed in cobbler (Ubuntu): | |
| milestone: | none β precise-alpha-1 |
| Changed in cobbler (Ubuntu Precise): | |
| status: | New β Triaged |
| Changed in cobbler (Ubuntu Oneiric): | |
| status: | New β Triaged |
| Changed in cobbler (Ubuntu Oneiric): | |
| assignee: | nobody β Robie Basak (racb) |
| Changed in cobbler (Ubuntu Precise): | |
| assignee: | nobody β Robie Basak (racb) |
Bug watches keep track of this bug in other bug trackers.