Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34305
HistoryFeb 21, 2022 - 5:46 a.m.

Information Disclosure

2022-02-2105:46:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.0004 Low

EPSS

Percentile

5.1%

cobbler is vulnerable to information disclosure. The vulnerability exists because the library does not properly restrict the config file accessibility, which allows an attacker who has access to the server to open an authenticated session with a cobbler daemon.

CPENameOperatorVersion
cobblerle3.3.0
cobblerle3.3.0