CVE-2018-10931
Severity CVSS v4.0:
Pending analysis
Type:
CWE-749
Exposed Dangerous Method or Function
Publication date:
09/08/2018
Last modified:
12/02/2023
Description
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:* | 2.6.0 (including) | 2.6.11 (including) |
| cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://access.redhat.com/errata/RHSA-2018:2372
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10931
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P5Q4ACIVZ5D4KSUDLGRTOKGGB4U42SD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMWK5KCCZXOGOYNR2H6BWDSABTQ5NYJA/



