ZeroHour

CVE-2021-40323

CVSS 3.1
9.8 critical
EPSS
87%p100
Published
()
Modified
Description

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

Vendors
cobbler project
Products
cobbler
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.