Search CVE reports


Toggle filters

11 – 20 of 20 results


CVE-2011-4952

Low priority

Some fixes available 3 of 5

cobbler: Web interface lacks CSRF protection when using Django framework

1 affected package

cobbler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler
Show less packages

CVE-2016-9605

Medium priority
Ignored

A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL...

2 affected packages

cobbler, maas-provision

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release Not in release Not in release
maas-provision Not in release Not in release Not in release
Show less packages

CVE-2018-1000226

Medium priority
Fixed

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC...

1 affected package

cobbler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release Not in release Not in release
Show less packages

CVE-2018-1000225

Medium priority
Fixed

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web...

1 affected package

cobbler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release Not in release Not in release
Show less packages

CVE-2018-10931

Medium priority
Fixed

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary...

1 affected package

cobbler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release Not in release Not in release
Show less packages

CVE-2017-1000469

Medium priority

Some fixes available 1 of 3

Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.

1 affected package

cobbler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release Not in release Not in release
Show less packages

CVE-2011-4953

High priority

Some fixes available 3 of 5

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as...

1 affected package

cobbler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler
Show less packages

CVE-2014-3225

Medium priority

Some fixes available 1 of 10

Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

2 affected packages

cobbler, maas-provision

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release Not in release Not in release
maas-provision Not in release Not in release Not in release
Show less packages

CVE-2012-2395

Medium priority
Ignored

Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.

2 affected packages

cobbler, maas-provision

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler Not in release
maas-provision Not in release
Show less packages

CVE-2011-1551

Medium priority

Not in release

SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root...

1 affected package

cobbler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cobbler
Show less packages