5.9
CVSSv3

CVE-2021-45081

Published: 20/02/2022 Updated: 08/08/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Cobbler up to and including 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cobbler project cobbler

Vendor Advisories

An issue was discovered in Cobbler through 331 Routines in several files use the HTTP protocol instead of the more secure HTTPS ...

Mailing Lists

Hello list, Last October 2021, I started a review on a subset of the Cobbler ecosystem ([1], [2] and [3]) using the master branch at the time the request was made [4] During the audit several issues were found and three of them, have been assigned with a CVE identifier 1) CVE-2021-45083 - unsafe permissions on sensitive files in /etc/cobbler ...