CVE Database
/

CVE-2021-45083

Back to search

CVE-2021-45083

Published: Feb 20, 2022

Modified: Aug 4, 2024

PUBLISHED

Description

An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2022-0c6402a6a3
vendor-advisory
x_refsource_FEDORA
FEDORA-2022-0649006be6
vendor-advisory
x_refsource_FEDORA
FEDORA-2022-f1510aa454
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now