Логотип exploitDog
bind:CVE-2018-1000226
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1000226

Количество 7

Количество 7

ubuntu логотип

CVE-2018-1000226

больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2018-1000226

больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 7.3
EPSS: Средний
nvd логотип

CVE-2018-1000226

больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2018-1000226

больше 7 лет назад

Cobbler version Verified as present in Cobbler versions 2.6.11+, but c ...

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-f88q-22g8-frcg

больше 3 лет назад

Cobbler Improper Validation of Security Tokens

CVSS3: 9.8
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2018:2590-1

больше 7 лет назад

Security update for cobbler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0046-1

около 5 лет назад

Security update for cobbler

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-1000226

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 9.8
61%
Средний
больше 7 лет назад
redhat логотип
CVE-2018-1000226

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 7.3
61%
Средний
больше 7 лет назад
nvd логотип
CVE-2018-1000226

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

CVSS3: 9.8
61%
Средний
больше 7 лет назад
debian логотип
CVE-2018-1000226

Cobbler version Verified as present in Cobbler versions 2.6.11+, but c ...

CVSS3: 9.8
61%
Средний
больше 7 лет назад
github логотип
GHSA-f88q-22g8-frcg

Cobbler Improper Validation of Security Tokens

CVSS3: 9.8
61%
Средний
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2590-1

Security update for cobbler

больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0046-1

Security update for cobbler

около 5 лет назад

Уязвимостей на страницу