Description
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cpqf-3c3r-c9g2 | Cobbler before 3.3.0 allows log poisoning |
Ubuntu USN |
USN-6475-1 | Cobbler vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:27:31.884Z
Reserved: 2021-08-30T00:00:00.000Z
Link: CVE-2021-40323
No data.
Status : Modified
Published: 2021-10-04T06:15:07.187
Modified: 2024-11-21T06:23:51.363
Link: CVE-2021-40323
OpenCVE Enrichment
No data.
Github GHSA
Ubuntu USN