Back

HIGH

cobbler: Arbitrary File Disclosure/Template Injection via generate_script RPC method

Published Oct 4, 2021

Description

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 4, 2021
Updated Aug 4, 2024
Reserved Aug 30, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 20, 2021
GHSA-CPQF-3C3R-C9G2