It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| cobbler(PyPI) | 2.6.0 | 3.0.0 | N/A |
CVSS Metrics