It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
References
Information
Published : 2018-08-09 13:29
Updated : 2023-02-12 15:31
NVD link : CVE-2018-10931
Mitre link : CVE-2018-10931
JSON object : View
CWE
CWE-749
Exposed Dangerous Method or Function
Products Affected
cobbler_project
- cobbler
redhat
- satellite