An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://github.com/cobbler/cobbler/releases | third party advisory release notes |
http://www.openwall.com/lists/oss-security/2022/02/18/3 | mailing list third party advisory patch |
https://bugzilla.suse.com/show_bug.cgi?id=1193683 | issue tracking third party advisory |