CVE-2021-40324

Related Vulnerabilities: CVE-2021-40324  

A flaw was found in cobbler. The flaw lies in cobblerd's anamon support, specifically the upload_log_data XMLRPC function. An anamon_enabled setting, if enabled, accepts unsanitized user-supplied parameters. This flaw allows an attacker to write arbitrary files to the system. The highest threat from this vulnerability is to confidentiality, integrity, and availability.

Description

A flaw was found in cobbler. The flaw lies in cobblerd's anamon support, specifically the upload_log_data XMLRPC function. An anamon_enabled setting, if enabled, accepts unsanitized user-supplied parameters. This flaw allows an attacker to write arbitrary files to the system. The highest threat from this vulnerability is to confidentiality, integrity, and availability.

Additional Information

  • Bugzilla 2006897: CVE-2021-40324 cobbler: Arbitrary file write via upload_log_data XMLRPC function
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2021-40324