RHEL 8 : cobbler (Unpatched Vulnerability)
Discription

The remote Redhat Enterprise Linux 8 host has one or more packages installed that are affected by multiple vulnerabilities that have been acknowledged by the vendor but will not be patched. cobbler: XMLRPC API endpoints are not correctly validating security tokens (CVE-2018-1000226) Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin.. This attack appear to be exploitable via network connectivity. Sending unauthenticated JavaScript payload to the Cobbler XMLRPC API (/cobbler_api). (CVE-2018-1000225) Note that Nessus has not tested for these issues but has instead relied on the package manager's report that the package is…Read More

Back to Main

Subscribe for the latest news: