{"id":"CVE-2021-40323","aliases":["GHSA-cpqf-3c3r-c9g2","PYSEC-2021-373"],"title":"Cobbler before 3.3.0 allows log poisoning","summary":"Cobbler before 3.3.0 allows log poisoning","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"cobbler","product":"cobbler","ecosystem":"pip","affected":["cobbler < 3.3.0"],"patched":["cobbler 3.3.0"],"published":"2021-10-05","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:09.105657730Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-cpqf-3c3r-c9g2","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40323"},{"url":"https://github.com/cobbler/cobbler/commit/d8f60bbf14a838c8c8a1dba98086b223e35fe70a"},{"url":"https://github.com/advisories/GHSA-cpqf-3c3r-c9g2"},{"url":"https://github.com/cobbler/cobbler"},{"url":"https://github.com/cobbler/cobbler/releases/tag/v3.3.0"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/cobbler/PYSEC-2021-373.yaml"}],"tags":["osv","pip","exploit-available"],"epss":0.86829,"epssPercentile":0.99741,"exploits":{"nuclei":["CVE-2021-40323"],"checkedAt":"2026-09-21T15:24:28.513Z"},"exploitAvailable":true,"ingestedAt":"2026-09-12T03:13:01.688Z","slug":"CVE-2021-40323","body":"## Overview\n\nCobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.\n\n## Affected packages\n\n- `cobbler < 3.3.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cobbler 3.3.0`","depth":"abyssal","depthScore":83,"depthScoreParts":{"impact":53.9,"likelihood":17.4,"exploitation":12,"ransomware":0},"changes":[]}