<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:16:50.826581+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-09952</id>
    <title>bdu:2024-09952</title>
    <updated>2026-10-07T01:16:50.837839+00:00</updated>
    <content>bdu:2024-09952</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-09952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-202410</id>
    <title>EUVD-2026-202410</title>
    <updated>2026-10-07T01:16:50.837884+00:00</updated>
    <content>EUVD-2026-202410</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-202410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47533</id>
    <title>fkie_cve-2024-47533</title>
    <updated>2026-10-07T01:16:50.837905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-47533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m26c-fcgh-cp6h</id>
    <title>GHSA-m26c-fcgh-cp6h — cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes</title>
    <updated>2026-10-07T01:16:50.837960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: cobbler</p>
<p>### Summary</p>
<p>utils.get_shared_secret() always returns -1 - allows anyone to connect to cobbler XML-RPC as user '' password -1 and make any changes.</p>
<p>### Details
utils.py get_shared_secret:
```
def get_shared_secret() -&gt; Union[str, int]:
    """
    The 'web.ss' file is regenerated each time cobblerd restarts and is used to agree on shared secret interchange
    between the web server and cobblerd, and also the CLI and cobblerd, when username/password access is not required.
    For the CLI, this enables root users to avoid entering username/pass if on the Cobbler server.</p>
<p>:return: The Cobbler secret which enables full access to Cobbler.
    """</p>
<p>try:
        with open("/var/lib/cobbler/web.ss", 'rb', encoding='utf-8') as fd:
            data = fd.read()
    except:
        return -1
    return str(data).strip()
```
Always returns `-1` because of the following exception:
```
binary mode doesn't take an encoding argument
```</p>
<p>This appears to have been introduced by commit 32c5cada013dc8daa7320a8eda9932c2814742b0 and so affects versions 3.0.0+.</p>
<p>### PoC
```
#!/usr/bin/python3</p>
<p>import ssl
import xmlrpc.client</p>
<p>params = { 'proto': 'https', 'host': 'COBBLER_SERVER', 'port': '443', 'username': '', 'password': -1 }
ssl_context = ssl._create_unverified_context()</p>
<p>url = '{proto}://{host}:{port}/cobbler_api'.format(**params)
if ssl_context:
    conn = xmlrpc.client.ServerProxy(url, context=ssl_context)
else:
    conn = xmlrpc.client.Server(url)</p>
<p>try:
    token = conn.login(para…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m26c-fcgh-cp6h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1411</id>
    <title>OESA-2025-1411 — cobbler security update</title>
    <updated>2026-10-07T01:16:50.838014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: cobbler</p>
<p>Cobbler is a network install server. Cobbler supports PXE, ISO virtualized installs, and re-installing existing Linux machines. The last two modes use a helper tool, &amp;amp;apos;koan&amp;amp;apos;, that integrates with cobbler. Cobbler&amp;amp;apos;s advanced features include importing distributions from DVDs and rsync mirrors, kickstart templating, integrated yum mirroring, and built-in DHCP/DNS Management. Cobbler has a XML-RPC API for integration with other applications.

Security Fix(es):</p>
<p>Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&amp;apos;&amp;apos;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.(CVE-2024-47533)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0370-1</id>
    <title>openSUSE-SU-2024:0370-1 — Security update for cobbler</title>
    <updated>2026-10-07T01:16:50.838044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for cobbler</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0370-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-316</id>
    <title>PYSEC-2026-316 — cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes</title>
    <updated>2026-10-07T01:16:50.838067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: cobbler</p>
<p>### Summary</p>
<p>utils.get_shared_secret() always returns -1 - allows anyone to connect to cobbler XML-RPC as user '' password -1 and make any changes.</p>
<p>### Details
utils.py get_shared_secret:
```
def get_shared_secret() -&gt; Union[str, int]:
    """
    The 'web.ss' file is regenerated each time cobblerd restarts and is used to agree on shared secret interchange
    between the web server and cobblerd, and also the CLI and cobblerd, when username/password access is not required.
    For the CLI, this enables root users to avoid entering username/pass if on the Cobbler server.</p>
<p>:return: The Cobbler secret which enables full access to Cobbler.
    """</p>
<p>try:
        with open("/var/lib/cobbler/web.ss", 'rb', encoding='utf-8') as fd:
            data = fd.read()
    except:
        return -1
    return str(data).strip()
```
Always returns `-1` because of the following exception:
```
binary mode doesn't take an encoding argument
 ```</p>
<p>This appears to have been introduced by commit 32c5cada013dc8daa7320a8eda9932c2814742b0 and so affects versions 3.0.0+.</p>
<p>### PoC
```
#!/usr/bin/python3</p>
<p>import ssl
 import xmlrpc.client</p>
<p>params = { 'proto': 'https', 'host': 'COBBLER_SERVER', 'port': '443', 'username': '', 'password': -1 }
ssl_context = ssl._create_unverified_context()
 
url = '{proto}://{host}:{port}/cobbler_api'.format(**params)
if ssl_context:
    conn = xmlrpc.client.ServerProxy(url, context=ssl_context)
else:
    conn = xmlrpc.client.Server(url)</p>
<p>try:
    token = conn.login(p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:4006-1</id>
    <title>SUSE-SU-2024:4006-1 — Security update for SUSE Manager Server 4.3</title>
    <updated>2026-10-07T01:16:50.838109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Server 4.3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:4006-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47533</id>
    <title>Withdrawn: UBUNTU-CVE-2024-47533</title>
    <updated>2026-10-07T01:16:50.838125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: cobbler</p>
<p>Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3491</id>
    <title>WID-SEC-W-2024-3491 — cobbler: Schwachstelle ermöglicht Erlangen von Administratorrechten</title>
    <updated>2026-10-07T01:16:50.838145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cobbler ausnutzen, um Administratorrechte zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3491"/>
  </entry>
</feed>
