Privilege escalation in Cobbler - CVE-2018-10931
Published: August 20, 2018 / Updated: August 21, 2018
Cobbler
Detailed vulnerability description
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The vulnerability exists due to exposure of all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote unauthenticated attacker can gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.