Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-10931

Опубликовано: 09 авг. 2018
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5
CVSS3: 9.8

Описание

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps-legacy/xenial

released

2.4.1-0ubuntu2+esm1
esm-apps/xenial

released

2.4.1-0ubuntu2+esm1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
esm-infra/focal

DNE

focal

DNE

Показывать по

EPSS

Процентиль: 99%
0.6786
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
около 8 лет назад

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS3: 9.8
nvd
около 8 лет назад

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

CVSS3: 9.8
debian
около 8 лет назад

It was found that cobbler 2.6.x exposed all functions from its Cobbler ...

suse-cvrf
почти 8 лет назад

Security update for cobbler

CVSS3: 9.8
github
больше 4 лет назад

Cobbler has Exposed Dangerous Method or Function

EPSS

Процентиль: 99%
0.6786
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2018-10931