Junglewise Threat Intelligence

CVE-2021-40323: PYSEC-2021-373 - Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template i

CVE-2021-40323 · Severity: low · CVSS 3.1 · Published 2021-10-04

Technologies: cobbler (PyPI). Vendors: PyPI.

Executive brief

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

Affected products

  • PyPI cobbler

Related threats