CVE-2021-40323: Code Injection
Published Oct 4, 2021
·Updated
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
Affected Software
2 affected componentsFixes available
pip/cobbler<3.3.0
3.3.0
Cobbler Project Cobbler<=3.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/cobblerto a version that resolves this vulnerability.Fixed in 3.3.0
Event History
Oct 4, 2021
CVE Published
via MITRE·05:37 AM
Data Sourced
via MITRE·05:37 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 5, 2021
Advisory Published
via GitHub·05:53 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-40323.
2
What is the severity of CVE-2021-40323?
The severity of CVE-2021-40323 is critical with a CVSS score of 9.8.
3
What is the affected software of CVE-2021-40323?
The affected software of CVE-2021-40323 is Cobbler before 3.3.0.
4
How does CVE-2021-40323 exploit log poisoning and result in Remote Code Execution?
CVE-2021-40323 exploits log poisoning through an XMLRPC method that logs to the logfile, allowing for template injection and remote code execution.
5
How can CVE-2021-40323 be fixed?
CVE-2021-40323 can be fixed by updating to Cobbler version 3.3.0 or later.