Search CVE reports
1 – 10 of 20 results
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and...
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | Not in release | Not in release | Not in release | — |
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | — | — | — |
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The...
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | — | — | — |
An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | — | — | — |
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with...
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | — | — | — |
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | Not in release | Not in release | Not in release |
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | Not in release | Not in release | Not in release |
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | Not in release | Not in release | Not in release |
Some fixes available 3 of 4
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.
2 affected packages
cobbler, maas-provision
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | — | — | — |
maas-provision | — | — | — | — |
Some fixes available 3 of 5
cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE
1 affected package
cobbler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cobbler | — | — | — | — |