VYPR

rpm package

suse/cobbler&distro=SUSE Manager Client Tools 12

pkg:rpm/suse/cobbler&distro=SUSE%20Manager%20Client%20Tools%2012

Vulnerabilities (11)

  • CVE-2021-45083Feb 20, 2022
    affected < 2.6.6-49.35.1fixed 2.6.6-49.35.1

    An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of

  • CVE-2020-13379Jun 3, 2020
    affected < 2.6.6-49.26.3fixed 2.6.6-49.26.3

    The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information abo

  • CVE-2020-12245Apr 24, 2020
    affected < 2.6.6-49.26.3fixed 2.6.6-49.26.3

    Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

  • CVE-2019-10215Oct 8, 2019
    affected < 2.6.6-49.26.3fixed 2.6.6-49.26.3

    Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.

  • CVE-2019-15043Sep 3, 2019
    affected < 2.6.6-49.26.3fixed 2.6.6-49.26.3

    In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

  • CVE-2016-9605Aug 22, 2018
    affected < 2.6.6-48.1fixed 2.6.6-48.1

    A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.

  • CVE-2018-1000226Aug 20, 2018
    affected < 2.6.6-49.14.1fixed 2.6.6-49.14.1

    Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation,

  • CVE-2018-1000225Aug 20, 2018
    affected < 2.6.6-49.14.1fixed 2.6.6-49.14.1

    Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin.. Th

  • CVE-2018-10931Aug 9, 2018
    affected < 2.6.6-49.14.1fixed 2.6.6-49.14.1

    It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

  • CVE-2017-7470Jul 27, 2018
    affected < 2.6.6-45.1fixed 2.6.6-45.1

    It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.

  • CVE-2017-1000469Jan 3, 2018
    affected < 2.6.6-49.9.1fixed 2.6.6-49.9.1

    Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.