REDHAT-BUG-1613861: Michael dehaan cobbler vulnerability
Cobbler CobblerXMLRPCInterface object exposes all its functions over XMLRPC. This allows an attacker to use internal the internal functions of the class, such as creating a token, or upload files.
Upstream issue:
https://github.com/cobbler/cobbler/issues/1916
Upstream patch:
https://github.com/cobbler/cobbler/pull/1921
References:
https://movermeyer.com/2018-08-02-privilege-escalation-exploits-in-cobblers-api/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1613861?
The severity of REDHAT-BUG-1613861 is high due to the potential for attackers to exploit exposed internal functions.
How do I fix REDHAT-BUG-1613861?
To fix REDHAT-BUG-1613861, update the Cobbler software to the latest version where the vulnerability is patched.
What types of attacks can REDHAT-BUG-1613861 facilitate?
REDHAT-BUG-1613861 can facilitate attacks such as unauthorized file uploads and token creation by exploiting the exposed XMLRPC functions.
Which software versions are affected by REDHAT-BUG-1613861?
All versions of Cobbler Cobbler that expose the CobblerXMLRPCInterface are affected by REDHAT-BUG-1613861.
Is authentication required to exploit REDHAT-BUG-1613861?
No, authentication is not required to exploit the vulnerability in REDHAT-BUG-1613861, which increases its risk.