ZeroHour

CVE-2018-10931

CVSS 3.0
9.8 critical
EPSS
68%p99
Published
()
Modified
Description

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

Vendors
cobbler projectredhat
Products
cobbler, satellite
Weakness
CWE-749
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.