cobbler@3.1.2 vulnerabilities
Network Boot and Update Server
-
latest version
3.3.7
-
first published
4 years ago
-
latest version published
5 days ago
-
licenses detected
- [3.1.2,)
Direct Vulnerabilities
Known vulnerabilities in the cobbler package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
cobbler is a network install server. Affected versions of this package are vulnerable to Improper Authentication due to the How to fix Improper Authentication? Upgrade |
[3.1.2,3.2.3)
[3.3.0,3.3.7)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Improper Input Validation by navigating to a vulnerable URL via How to fix Improper Input Validation? There is no fixed version for |
[0,)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Improper Authorization when it is configured to authenticate via How to fix Improper Authorization? Upgrade |
[,3.2.3)
[3.3.0,3.3.1)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Improper Input Validation due to improper sanitization of the How to fix Improper Input Validation? Upgrade |
[,3.3.1)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Information Exposure. The files in How to fix Information Exposure? Upgrade |
[,3.2.3)
[3.3.0,3.3.1)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Insecure Defaults as a lot of cobbler server entry points are served on HTTP protocol rather than HTTPS protocol. How to fix Insecure Defaults? Upgrade |
[,3.2.3)
[3.3.0,3.3.1)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Arbitrary Code Execution via lacking template sanitization of imported modules in the How to fix Arbitrary Code Execution? Upgrade |
[,3.2.3)
[3.3.0,3.3.1)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Arbitrary File Write via the Note: Exploitable only if the How to fix Arbitrary File Write? Upgrade |
[,3.2.2)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Arbitrary Code Execution the As many How to fix Arbitrary Code Execution? Upgrade |
[,3.2.2)
|
cobbler is a network install server. Affected versions of this package are vulnerable to Improper Authorization via an unknown attack vector, allowing settings modification. How to fix Improper Authorization? Upgrade |
[,3.2.2)
|