CVE-2018-10931
09.08.2018, 20:29
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.Enginsight
Vendor | Product | Version |
---|---|---|
cobbler_project | cobbler | 2.6.0 ≤ 𝑥 ≤ 2.6.11 |
redhat | satellite | 5.6 |
redhat | satellite | 5.7 |
redhat | satellite | 5.8 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References