Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3281 | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue. |
Github GHSA |
GHSA-m26c-fcgh-cp6h | cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 18 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cobbler Project
Cobbler Project cobbler |
|
| CPEs | cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cobbler Project
Cobbler Project cobbler |
|
| Metrics |
ssvc
|
Mon, 18 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue. | |
| Title | Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-18T18:24:07.378Z
Reserved: 2024-09-25T21:46:10.929Z
Link: CVE-2024-47533
Updated: 2024-11-18T18:23:31.482Z
Status : Deferred
Published: 2024-11-18T17:15:11.563
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-47533
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA