The Cobbler Project Cobbler vulnerabilities
2 known vulnerabilities affecting the_cobbler_project/cobbler.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2016-9605MEDIUMCVSS 6.1v2.6.11-12018-08-22
CVE-2016-9605 [MEDIUM] CWE-79 CVE-2016-9605: A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid paramete
A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.
cvelistv5nvd
CVE-2018-10931CRITICALCVSS 9.8v2.6.x2018-08-09
CVE-2018-10931 [CRITICAL] CWE-749 CVE-2018-10931: It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XML
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
cvelistv5nvd