Description
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
Published: 2024-11-18
Score: 9.8 Critical
EPSS: 70.9% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-3281 Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
Github GHSA Github GHSA GHSA-m26c-fcgh-cp6h cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00245}

epss

{'score': 0.00199}


Mon, 18 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Cobbler Project
Cobbler Project cobbler
CPEs cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:*
Vendors & Products Cobbler Project
Cobbler Project cobbler
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
Description Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
Title Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cobbler Project Cobbler
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-18T18:24:07.378Z

Reserved: 2024-09-25T21:46:10.929Z

Link: CVE-2024-47533

cve-icon Vulnrichment

Updated: 2024-11-18T18:23:31.482Z

cve-icon NVD

Status : Deferred

Published: 2024-11-18T17:15:11.563

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-47533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses