Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8787-63px-3m23

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Cobbler has Exposed Dangerous Method or Function

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

Пакеты

Наименование

cobbler

pip
Затронутые версииВерсия исправления

>= 2.6.0, < 3.0.0

3.0.0

EPSS

Процентиль: 99%
0.67782
Средний

9.8 Critical

CVSS3

Дефекты

CWE-749

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS3: 9.8
redhat
больше 7 лет назад

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS3: 9.8
nvd
больше 7 лет назад

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS3: 9.8
debian
больше 7 лет назад

It was found that cobbler 2.6.x exposed all functions from its Cobbler ...

suse-cvrf
больше 7 лет назад

Security update for cobbler

EPSS

Процентиль: 99%
0.67782
Средний

9.8 Critical

CVSS3

Дефекты

CWE-749