Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2021-45081

Published: 20 February 2022

An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.

Notes

AuthorNote
nickgalanis
Using HTTPS everywhere requires a deep knowledge of how customers
implements cobbler in their network and how do they manage certificates.
The maintainer decided to not patch this vulnerability, and will keep attention
on this in order to create a certificate enrolling and trusting layer in the
python code for the future. Thus, this CVE is marked as ignored.

Priority

Medium

Cvss 3 Severity Score

5.9

Score breakdown

Status

Package Release Status
cobbler
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
upstream
Released (3.3.1)
xenial Ignored
(see notes)

Severity score breakdown

Parameter Value
Base score 5.9
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N