---
id: CVE-2011-4952
aliases:
  - GHSA-9fqr-pqc9-f7pj
  - PYSEC-2026-624
title: Cobbler Web Interface Lacks CSRF Protection
summary: Cobbler Web Interface Lacks CSRF Protection
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: cobbler
product: cobbler
ecosystem: pip
affected:
  - cobbler < 2.6.0
patched:
  - cobbler 2.6.0
published: '2022-04-22'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9fqr-pqc9-f7pj'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2011-4952'
  - url: >-
      https://github.com/cobbler/cobbler/commit/18eb1c06779b37d89dfb2962a08236dd1bab24a6
  - url: >-
      https://github.com/cobbler/cobbler/commit/4bee30b4086a8d845bea5d39d6f2cba1f4a396aa
  - url: 'https://access.redhat.com/security/cve/cve-2011-4952'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4952'
  - url: 'https://github.com/cobbler/cobbler'
  - url: 'https://security-tracker.debian.org/tracker/CVE-2011-4952'
  - url: 'http://www.openwall.com/lists/oss-security/2012/04/12/10'
tags:
  - osv
  - pip
epss: 0.00635
epssPercentile: 0.48744
ingestedAt: '2026-07-08T18:25:47.850Z'
---

## Overview

cobbler: Web interface lacks CSRF protection when using Django framework

## Affected packages

- `cobbler < 2.6.0`

## Remediation

Upgrade to a patched release:

- `cobbler 2.6.0`
