Fedora 41: cobbler 2024-4f04edd1e7 Security Advisory Updates
Summary
Cobbler is a network install server. Cobbler supports PXE, ISO
virtualized installs, and re-installing existing Linux machines. The
last two modes use a helper tool, 'koan', that integrates with cobbler.
Cobbler's advanced features include importing distributions from DVDs
and rsync mirrors, kickstart templating, integrated yum mirroring, and
built-in DHCP/DNS Management. Cobbler has a XML-RPC API for integration
with other applications.
Update Information:
Update to 3.3.7 - CVE-2024-47533
Change Log
* Sun Nov 17 2024 Orion Poplawski
References
[ 1 ] Bug #2326874 - cobbler-3.3.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2326874
[ 2 ] Bug #2327082 - CVE-2024-47533 cobbler: Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2327082
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4f04edd1e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label