Описание
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
A flaw was found in cobbler. This flaw lies in the token validation and could allow an attacker to bypass authorization and modify settings.
Отчет
This vulnerability does not affect any Red Hat supported product.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | rhn-tools:1.0/cobbler | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2006904cobbler: Authorization bypass allows modifying settings
EPSS
Процентиль: 71%
0.01406
Низкий
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 5 лет назад
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
CVSS3: 7.5
nvd
почти 5 лет назад
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
CVSS3: 7.5
debian
почти 5 лет назад
Cobbler before 3.3.0 allows authorization bypass for modification of s ...
CVSS3: 7.5
github
почти 5 лет назад
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
EPSS
Процентиль: 71%
0.01406
Низкий
7.5 High
CVSS3