Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10931

Опубликовано: 09 авг. 2018
Источник: redhat
CVSS3: 9.8

Описание

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

An API-exposure flaw was found in cobbler, where it exported CobblerXMLRPCInterface private functions over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain important privileges within cobbler, as well as upload files to an arbitrary location in the daemon context.

Меры по смягчению последствий

If SELinux is enabled, it might prevent some locations from accepting uploaded files from the attacker. This prevents some basic attacks allowing remote code execution, although it would not exclude all other possibilities.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8cobblerNot affected
Red Hat Satellite 5.6cobblerFixedRHSA-2018:237209.08.2018
Red Hat Satellite 5.7cobblerFixedRHSA-2018:237209.08.2018
Red Hat Satellite 5.8cobblerFixedRHSA-2018:237209.08.2018

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-749
https://bugzilla.redhat.com/show_bug.cgi?id=1613861cobbler: CobblerXMLRPCInterface exports all its methods over XMLRPC

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS3: 9.8
nvd
больше 7 лет назад

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS3: 9.8
debian
больше 7 лет назад

It was found that cobbler 2.6.x exposed all functions from its Cobbler ...

suse-cvrf
больше 7 лет назад

Security update for cobbler

CVSS3: 9.8
github
больше 3 лет назад

Cobbler has Exposed Dangerous Method or Function

9.8 Critical

CVSS3