CVE-2021-40324: Malicious File Upload
Published Oct 4, 2021
·Updated
Cobbler before 3.3.0 allows arbitrary file write operations via uploadlogdata.
Affected Software
2 affected componentsFixes available
pip/cobbler<3.3.0
3.3.0
Cobbler Project Cobbler<=3.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/cobblerto a version that resolves this vulnerability.Fixed in 3.3.0
Event History
Oct 4, 2021
CVE Published
via MITRE·05:39 AM
Data Sourced
via MITRE·05:39 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 5, 2021
Advisory Published
via GitHub·05:53 PM
Frequently Asked Questions
1
What is CVE-2021-40324?
CVE-2021-40324 is a vulnerability in Cobbler before version 3.3.0 that allows arbitrary file write operations via upload_log_data.
2
How severe is CVE-2021-40324?
CVE-2021-40324 has a severity score of 7.5 (high).
3
How does CVE-2021-40324 impact Cobbler?
CVE-2021-40324 allows attackers to perform arbitrary file write operations in Cobbler before version 3.3.0 via the upload_log_data functionality.
4
How can I fix CVE-2021-40324?
To fix CVE-2021-40324, upgrade to Cobbler version 3.3.0 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-40324?
The Common Weakness Enumeration (CWE) ID for CVE-2021-40324 is CWE-434.