Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cobbler Project
Cobbler Project cobbler |
|
CPEs | cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cobbler Project
Cobbler Project cobbler |
|
Metrics |
ssvc
|
Mon, 18 Nov 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue. | |
Title | Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-18T16:33:55.229Z
Updated: 2024-11-18T18:24:07.378Z
Reserved: 2024-09-25T21:46:10.929Z
Link: CVE-2024-47533
Vulnrichment
Updated: 2024-11-18T18:23:31.482Z
NVD
Status : Awaiting Analysis
Published: 2024-11-18T17:15:11.563
Modified: 2024-11-19T21:57:56.293
Link: CVE-2024-47533
Redhat
No data.