Vulnerabilities > Cobbler Project > Cobbler > 0.4.6

DATE CVE VULNERABILITY TITLE RISK
2022-03-11 CVE-2022-0860 Improper Authorization vulnerability in multiple products
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
network
low complexity
cobbler-project fedoraproject CWE-285
critical
9.1
2022-02-20 CVE-2021-45081 Cleartext Transmission of Sensitive Information vulnerability in Cobbler Project Cobbler
An issue was discovered in Cobbler through 3.3.1.
network
high complexity
cobbler-project CWE-319
5.9
2022-02-20 CVE-2021-45083 Incorrect Default Permissions vulnerability in multiple products
An issue was discovered in Cobbler before 3.3.1.
local
low complexity
cobbler-project fedoraproject CWE-276
7.1
2022-02-19 CVE-2021-45082 Command Injection vulnerability in multiple products
An issue was discovered in Cobbler before 3.3.1.
7.8
2021-10-04 CVE-2021-40323 Code Injection vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
network
low complexity
cobbler-project CWE-94
7.5
2021-10-04 CVE-2021-40324 Unrestricted Upload of File with Dangerous Type vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
network
low complexity
cobbler-project CWE-434
5.0
2021-10-04 CVE-2021-40325 Unspecified vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
network
low complexity
cobbler-project
7.5