CVE-2018-10931
critical · 9.8It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
9.8
CVSS
68.1%
EPSS (exploit prob.)
99th
EPSS percentile
2018-08-09
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-749
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cobbler_project | cobbler | >= 2.6.0, <= 2.6.11 |
| redhat | satellite | 5.6 |
| redhat | satellite | 5.7 |
| redhat | satellite | 5.8 |
Check a specific version with /api/v1/cve/match.
References
- https://access.redhat.com/errata/RHSA-2018:2372
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10931
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P5Q4ACIVZ5D4KSUDLGRTOKGGB4U42SD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMWK5KCCZXOGOYNR2H6BWDSABTQ5NYJA/
- https://access.redhat.com/errata/RHSA-2018:2372
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10931
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P5Q4ACIVZ5D4KSUDLGRTOKGGB4U42SD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMWK5KCCZXOGOYNR2H6BWDSABTQ5NYJA/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-10931