Lucene search

K
redhatcveRedhat.comRH:CVE-2018-10931
HistoryAug 09, 2018 - 3:18 p.m.

CVE-2018-10931

2018-08-0915:18:52
redhat.com
access.redhat.com
16

0.007 Low

EPSS

Percentile

79.8%

An API-exposure flaw was found in cobbler, where it exported CobblerXMLRPCInterface private functions over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain important privileges within cobbler, as well as upload files to an arbitrary location in the daemon context.

Mitigation

If SELinux is enabled, it might prevent some locations from accepting uploaded files from the attacker. This prevents some basic attacks allowing remote code execution, although it would not exclude all other possibilities.