QID 730828
Date Published: 2023-06-19
QID 730828: Cobbler Remote Code Execution(RCE) Vulnerability
Cobbler is a versatile Linux deployment server
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
Affected Versions :
Cobbler before 3.3.0
QID Detection Logic(Un-authenticated)
It uses two step queries , it extracts profile name then feeds profile name to second request in order to check password file on system
On successful exploitation it allows an attacker to execute remote code.
Solution
Vendor has released fix. Refer to advisory here for updates and patch information.
Vendor References
- Cobbler V3.3.0 -
github.com/cobbler/cobbler/releases/tag/v3.3.0
CVEs related to QID 730828
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Cobbler V3.3.0 |
|