CVE-2009-4261 describes multiple directory traversal vulnerabilities within the iallocator framework of Ganeti versions 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2. These flaws, stemming from "path sanitization errors," allow both remote attackers via the HTTP RAPI and local users via gnt-* commands to execute arbitrary programs and potentially gain privileges through crafted external script names. With a CVSS score of 7.5, this vulnerability is considered highly severe, indicating a network-exploitable attack with low complexity that can lead to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.4CPE matchmatch criteria | cpe:2.3:a:roman_marxer:ganeti:1.2.4:*:*:*:*:*:*:* | ||
1.2.5CPE matchmatch criteria | cpe:2.3:a:roman_marxer:ganeti:1.2.5:*:*:*:*:*:*:* | ||
1.2.6CPE matchmatch criteria | cpe:2.3:a:roman_marxer:ganeti:1.2.6:*:*:*:*:*:*:* | ||
1.2.7CPE matchmatch criteria | cpe:2.3:a:roman_marxer:ganeti:1.2.7:*:*:*:*:*:*:* | ||
1.2.8CPE matchmatch criteria | cpe:2.3:a:roman_marxer:ganeti:1.2.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.