Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.147788
Category:Web application abuses
Title:Cobbler < 3.3.2 Improper Authorization Vulnerability
Summary:Cobbler is prone to an improper authorization vulnerability.
Description:Summary:
Cobbler is prone to an improper authorization vulnerability.

Vulnerability Insight:
If PAM is correctly configured and a user account is set to
expired, the expired user-account is still able to successfully log into Cobbler in all places
(Web UI, CLI & XMLRPC-API).

The same applies to user accounts with passwords set to be expired.

Affected Software/OS:
Cobbler version 3.3.1 and prior.

Solution:
Update to version 3.3.2 or later.

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-0860
https://huntr.dev/bounties/c458b868-63df-414e-af10-47e3745caa1d
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DYWYHWVVRUSPCV5SWBOSAMQJQLTSBTKY/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D4KCNZYBQC2FM5SEEDRQZO4LRZ4ZECMG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYSHMF6MEIITFAG7EJ3IQKVUN7MDV2XM/
https://github.com/cobbler/cobbler/commit/9044aa990a94752fa5bd5a24051adde099280bfa
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.