Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f88q-22g8-frcg

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Cobbler Improper Validation of Security Tokens

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

Пакеты

Наименование

cobbler

pip
Затронутые версииВерсия исправления

<= 2.6.11

3.0.0

EPSS

Процентиль: 98%
0.61011
Средний

9.8 Critical

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 7.3
redhat
больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 9.8
nvd
больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 9.8
debian
больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but c ...

suse-cvrf
больше 7 лет назад

Security update for cobbler

EPSS

Процентиль: 98%
0.61011
Средний

9.8 Critical

CVSS3

Дефекты

CWE-732