An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cobbler | Cobbler_project | * | 3.3.1 (including) |
| Cobbler | Ubuntu | esm-apps/xenial | * |
| Cobbler | Ubuntu | trusty | * |
| Cobbler | Ubuntu | upstream | * |
| Cobbler | Ubuntu | xenial | * |