Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-40324

Опубликовано: 20 сент. 2021
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

A flaw was found in cobbler. The flaw lies in cobblerd's anamon support, specifically the upload_log_data XMLRPC function. An anamon_enabled setting, if enabled, accepts unsanitized user-supplied parameters. This flaw allows an attacker to write arbitrary files to the system. The highest threat from this vulnerability is to confidentiality, integrity, and availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8rhn-tools:1.0/cobblerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2006897cobbler: Arbitrary file write via upload_log_data XMLRPC function

EPSS

Процентиль: 99%
0.68635
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

CVSS3: 7.5
nvd
почти 5 лет назад

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

CVSS3: 7.5
debian
почти 5 лет назад

Cobbler before 3.3.0 allows arbitrary file write operations via upload ...

CVSS3: 7.5
github
почти 5 лет назад

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

EPSS

Процентиль: 99%
0.68635
Средний

8.1 High

CVSS3