CVE-2018-1000226
Cobbler Improper Validation of Security Tokens
Record summary
CVE-2018-1000226 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
cobblerBrowse PyPI / cobbler | GitHub Advisory | Before 3.0.0 · Fixed in 3.0.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALCobbler - Authentication BypassCVSS 9.8
Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ and possibly even older versions, may be vulnerable to an authentication bypass vulnerability in XMLRPC API (/cobbler_api) that can result in privilege escalation, data manipulation or exfiltration, and LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.
Impact
Unauthenticated attackers can bypass authentication to gain unauthorized access, leading to privilege escalation, data manipulation or exfiltration, and LDAP credential harvesting.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the authentication bypass vulnerability in Cobbler.
Source: ProjectDiscovery