CVE-2021-45083 is a local privilege escalation vulnerability affecting Cobbler versions prior to 3.3.1. It allows non-privileged local users to read sensitive files in /etc/cobbler, specifically users.digest and settings.yaml. These files contain SHA2-512 password digests and hashed default passwords, which can be exploited to gain unauthorized access. The vulnerability has a CVSS v3.1 score of 7.1 (HIGH), indicating a low attack complexity and requiring local access, but leading to high confidentiality and integrity impacts. An attacker could easily guess weak passwords from the exposed digests. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.1CPE matchmatch criteria | cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.