CVE-2018-10931
09.08.2018, 20:29
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cobbler_project | cobbler | 2.6.0 ≤ 𝑥 ≤ 2.6.11 |
| redhat | satellite | 5.6 |
| redhat | satellite | 5.7 |
| redhat | satellite | 5.8 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References