CVE-2021-40323Critical· 9.8▾ AbyssalPoC availableCobbler before 3.3.0 allows log poisoning
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 17.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
87%
Nuclei ×1 (last check)
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
cobbler < 3.3.0Upgrade to a patched release:
cobbler 3.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-40325High· 7.5Cobbler before 3.3.0 allows authorization bypass for modification of settings.
CVE-2021-40324High· 7.5Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
CVE-2014-3225MediumCobbler Path Traversal vulnerability
CVE-2021-45082High· 7.8Command Injection in Cobbler
CVE-2021-45083High· 7.1Incorrect Default Permissions in Cobbler
CVE-2018-1000225Medium· 6.1Cobbler XSS Vulnerability