First published: Mon Oct 04 2021(Updated: )
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cobbler Project Cobbler | <=3.3.0 | |
pip/cobbler | <3.3.0 | 3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40324 is a vulnerability in Cobbler before version 3.3.0 that allows arbitrary file write operations via upload_log_data.
CVE-2021-40324 has a severity score of 7.5 (high).
CVE-2021-40324 allows attackers to perform arbitrary file write operations in Cobbler before version 3.3.0 via the upload_log_data functionality.
To fix CVE-2021-40324, upgrade to Cobbler version 3.3.0 or later.
The Common Weakness Enumeration (CWE) ID for CVE-2021-40324 is CWE-434.