Vulnerabilities > Cobbler Project > Cobbler > 2.6.10

DATE CVE VULNERABILITY TITLE RISK
2022-03-11 CVE-2022-0860 Improper Authorization vulnerability in multiple products
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
network
low complexity
cobbler-project fedoraproject CWE-285
critical
9.1
2022-02-20 CVE-2021-45081 Cleartext Transmission of Sensitive Information vulnerability in Cobbler Project Cobbler
An issue was discovered in Cobbler through 3.3.1.
network
high complexity
cobbler-project CWE-319
5.9
2021-10-04 CVE-2021-40323 Code Injection vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
network
low complexity
cobbler-project CWE-94
7.5
2021-10-04 CVE-2021-40324 Unrestricted Upload of File with Dangerous Type vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
network
low complexity
cobbler-project CWE-434
5.0
2021-10-04 CVE-2021-40325 Unspecified vulnerability in Cobbler Project Cobbler
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
network
low complexity
cobbler-project
7.5
2018-08-09 CVE-2018-10931 Exposed Dangerous Method or Function vulnerability in multiple products
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.
network
low complexity
cobbler-project redhat CWE-749
critical
9.8