PT-2022-12302 · Cobbler · Cobbler

Paolo Perego

·

Published

2022-02-20

·

Updated

2025-05-16

·

CVE-2021-45081

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cobbler versions prior to 3.3.2
Description An issue was discovered where routines in several files use the HTTP protocol instead of the more secure HTTPS.
Recommendations For Cobbler versions prior to 3.3.2, consider updating to a version that uses HTTPS instead of HTTP to enhance security. As a temporary workaround, consider restricting access to the affected routines until a patch is available.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-45081
OESA-2025-1467
OESA-2025-1468
OESA-2025-1469
OESA-2025-1527

Affected Products

Cobbler