First published: Sun Feb 20 2022(Updated: )
An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cobbler Project Cobbler | <=3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45081 is a vulnerability discovered in Cobbler through version 3.3.1 that allows the use of the insecure HTTP protocol instead of HTTPS.
CVE-2021-45081 has a severity rating of medium with a score of 5.9.
Cobbler versions up to and including 3.3.1 are affected by CVE-2021-45081.
To fix CVE-2021-45081, it is recommended to update to a version of Cobbler that includes the necessary security patches.
You can find more information about CVE-2021-45081 on the following references: [http://www.openwall.com/lists/oss-security/2022/02/18/3](http://www.openwall.com/lists/oss-security/2022/02/18/3), [https://bugzilla.suse.com/show_bug.cgi?id=1193683](https://bugzilla.suse.com/show_bug.cgi?id=1193683), [https://github.com/cobbler/cobbler/releases](https://github.com/cobbler/cobbler/releases)