CVE-2021-45083
Ubuntu Security Notice USN-6475-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.
Se ha detectado un problema en Cobbler versiones anteriores a 3.3.1. Los archivos en /etc/cobbler son legibles para el mundo. Dos de esos archivos contienen información confidencial que puede ser expuesta a un usuario local que tenga acceso no privilegiado al servidor. El archivo users.digest contiene el resumen sha2-512 de los usuarios en una instalación local de Cobbler. En el caso de una contraseña fácil de adivinar, es trivial obtener la cadena en texto plano. El archivo settings.yaml contiene secretos como la contraseña por defecto con hash
An update that solves 6 vulnerabilities and has 6 fixes is now available. This update for cobbler fixes the following issues. Fixed unsafe permissions on sensitive files. Fixed incomplete template sanitation. Fixed Remote Code Execution in the XMLRPC API which additionally allowed arbitrary file read and write as root. The following non-security bugs were fixed. Boot_loader is not set destination directory is not existing.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-16 CVE Reserved
- 2022-02-20 CVE Published
- 2024-08-04 CVE Updated
- 2025-07-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1193671 | Issue Tracking | |
https://github.com/cobbler/cobbler/releases | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.openwall.com/lists/oss-security/2022/02/18/3 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cobbler Project Search vendor "Cobbler Project" | Cobbler Search vendor "Cobbler Project" for product "Cobbler" | < 3.3.1 Search vendor "Cobbler Project" for product "Cobbler" and version " < 3.3.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 36 Search vendor "Fedoraproject" for product "Fedora" and version "36" | - |
Affected
|