CVE-2018-10931

CRITICAL9.8EPSS 36.0%

Cobbler has Exposed Dangerous Method or Function

Published: 5/13/2022Modified: 11/8/2023
Also known as:GHSA-8787-63px-3m23

Description

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (14)