An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cobbler | Cobbler_project | * | 3.3.1 (including) |
Cobbler | Ubuntu | esm-apps/xenial | * |
Cobbler | Ubuntu | trusty | * |
Cobbler | Ubuntu | upstream | * |
Cobbler | Ubuntu | xenial | * |