{"id":"CVE-2021-40324","aliases":["GHSA-4cfr-gjfx-fj3x","PYSEC-2021-374"],"title":"Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.","summary":"Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","vendor":"cobbler","product":"cobbler","ecosystem":"pip","affected":["cobbler < 3.3.0"],"patched":["cobbler 3.3.0"],"published":"2021-10-05","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:09.069893513Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4cfr-gjfx-fj3x","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40324"},{"url":"https://github.com/cobbler/cobbler/commit/d8f60bbf14a838c8c8a1dba98086b223e35fe70a"},{"url":"https://github.com/advisories/GHSA-4cfr-gjfx-fj3x"},{"url":"https://github.com/cobbler/cobbler"},{"url":"https://github.com/cobbler/cobbler/releases/tag/v3.3.0"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/cobbler/PYSEC-2021-374.yaml"}],"tags":["osv","pip"],"epss":0.68635,"epssPercentile":0.99329,"ingestedAt":"2026-09-12T03:13:01.652Z","slug":"CVE-2021-40324","body":"## Overview\n\nCobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.\n\n## Affected packages\n\n- `cobbler < 3.3.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cobbler 3.3.0`","depth":"twilight","depthScore":55,"depthScoreParts":{"impact":41.3,"likelihood":13.7,"exploitation":0,"ransomware":0},"changes":[]}