UBUNTU-CVE-2021-45083
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-45083
UBUNTU-CVE-2021-45083
Summary:
Details: An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.
References: https://ubuntu.com/security/CVE-2021-45083, https://github.com/cobbler/cobbler/releases, https://www.openwall.com/lists/oss-security/2022/02/18/3, https://ubuntu.com/security/notices/USN-6475-1, https://www.cve.org/CVERecord?id=CVE-2021-45083
Affected packages
Package
Name: cobbler
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
