Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-45083

EPSS 0.03% · P9
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-45083

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cobbler 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cobbler是一款网络安装服务器套件,它主要用于快速建立Linux网络安装环境。 Cobbler 3.3.1之前版本存在安全漏洞,该漏洞源于/etc/cobbler中的文件是公开可读的。其中两个文件包含一些敏感信息,这些信息可能会暴露给对服务器具有非特权访问权限的本地用户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2021-45083

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-45083

登录查看更多情报信息。

Same Patch Batch · n/a · 2022-02-20 · 7 CVEs total

CVE-2021-467017.2 HIGHPreMid 访问控制错误漏洞
CVE-2022-25375Linux kernel 安全漏洞
CVE-2022-25372Pritunl-client权限许可和访问控制问题漏洞
CVE-2022-23848Alluxio 安全漏洞
CVE-2021-45081Cobbler 加密问题漏洞
CVE-2021-45007Plesk Cms 跨站请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-45083

No comments yet


Leave a comment