CVE-2021-40323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
04/10/2021
Last modified:
12/10/2021

Description

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cobbler_project:cobbler:*:*:*:*:*:*:*:* 3.3.0 (including)