PT-2024-8393 · Cobbler+1 · Cobbler+1

Opoplawski

·

Published

2024-11-17

·

Updated

2025-04-18

·

CVE-2024-47533

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cobbler versions 3.0.0 through 3.2.2 Cobbler versions 3.3.0 through 3.3.6
Description The issue is related to an improper authentication vulnerability in Cobbler, a Linux installation server. This vulnerability allows anyone with network access to a Cobbler server to gain full control of the server. The utils.get shared secret() function always returns -1, which enables unauthorized access to the Cobbler XML-RPC as user `` with password -1. This gives an attacker the ability to make any changes to the server.
Recommendations For Cobbler versions 3.0.0 through 3.2.2, update to version 3.2.3 or later. For Cobbler versions 3.3.0 through 3.3.6, update to version 3.3.7 or later. As a temporary workaround, consider restricting access to the Cobbler XML-RPC endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09952
CVE-2024-47533
GHSA-M26C-FCGH-CP6H
OESA-2025-1411
OESA-2025-1412
OESA-2025-1413
OESA-2025-1414
OESA-2025-1435
OPENSUSE-SU-2024:0370-1
OPENSUSE-SU-2024:0382-1
OPENSUSE-SU-2024:14512-1
OPENSUSE-SU-2024_4007-1
SUSE-SU-2024:4006-1
SUSE-SU-2024:4007-1

Affected Products

Cobbler
Suse