{"id":"CVE-2021-40325","aliases":["GHSA-cr3f-r24j-3chw","PYSEC-2021-375"],"title":"Cobbler before 3.3.0 allows authorization bypass for modification of settings.","summary":"Cobbler before 3.3.0 allows authorization bypass for modification of settings.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","vendor":"cobbler","product":"cobbler","ecosystem":"pip","affected":["cobbler < 3.3.0"],"patched":["cobbler 3.3.0"],"published":"2021-10-05","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:09.153279474Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-cr3f-r24j-3chw","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40325"},{"url":"https://github.com/cobbler/cobbler/commit/d8f60bbf14a838c8c8a1dba98086b223e35fe70a"},{"url":"https://github.com/advisories/GHSA-cr3f-r24j-3chw"},{"url":"https://github.com/cobbler/cobbler"},{"url":"https://github.com/cobbler/cobbler/releases/tag/v3.3.0"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/cobbler/PYSEC-2021-375.yaml"}],"tags":["osv","pip"],"epss":0.01406,"epssPercentile":0.71443,"ingestedAt":"2026-09-12T03:13:01.688Z","slug":"CVE-2021-40325","body":"## Overview\n\nCobbler before 3.3.0 allows authorization bypass for modification of settings.\n\n## Affected packages\n\n- `cobbler < 3.3.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cobbler 3.3.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}