Security Advisory

CVE-2018-10931

9.8
CRITICAL

Vulnerability Description

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
Published Date August 9, 2018
Official Source NIST NVD Advisory