CVE-2009-5021: High severity cobbler vulnerability
Cobbler before 1.6.1 does not properly determine whether an installation has the default password, which makes it easier for attackers to obtain access by using this password.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5021?
CVE-2009-5021 is considered to have a medium severity due to the potential for unauthorized access using default passwords.
How do I fix CVE-2009-5021?
To fix CVE-2009-5021, users should upgrade to Cobbler version 1.6.1 or later, where the default password issue is addressed.
Which versions of Cobbler are affected by CVE-2009-5021?
CVE-2009-5021 affects Cobbler versions prior to 1.6.1, including versions 0.2.1 through 1.4.3.
What is the cause of CVE-2009-5021?
CVE-2009-5021 arises from Cobbler's failure to verify whether an installation is running with the default password.
Is it safe to use Cobbler versions affected by CVE-2009-5021?
Using affected versions of Cobbler poses a security risk due to the likelihood of unauthorized access with default credentials.