Executive brief
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
Affected products
- PyPI cobbler
Junglewise Threat Intelligence
CVE-2021-40323 · Severity: low · CVSS 3.1 · Published 2021-10-04
Technologies: cobbler (PyPI). Vendors: PyPI.
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.