Описание
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cobbler | removed | package |
EPSS
Процентиль: 100%
0.93171
Критический
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 4 лет назад
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
CVSS3: 9.1
redhat
больше 4 лет назад
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
CVSS3: 9.8
nvd
больше 4 лет назад
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
EPSS
Процентиль: 100%
0.93171
Критический