Vulnerability record · CVE-2021-40324 · published 4 October 2021
CVE-2021-40324: Cobbler upload_log_data arbitrary file write
Cobbler Project · Cobbler
Cobbler before 3.3.0 allows arbitrary file write operations through the upload_log_data function. Because the flaw is an unrestricted file upload (CWE-434) reachable over the network without credentials, an attacker can place files anywhere the Cobbler service can write, which matters for any exposed provisioning server.
Description
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file write with a 7.5 CVSS score and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
Cobbler before 3.3.0 allows arbitrary file write operations through the upload_log_data function. Because the flaw is an unrestricted file upload (CWE-434) reachable over the network without credentials, an attacker can place files anywhere the Cobbler service can write, which matters for any exposed provisioning server.
Impact
An attacker gains the ability to write arbitrary files on the Cobbler host, which can lead to code execution or service takeover depending on where files land. Integrity is rated High; confidentiality and availability are not affected per the CVSS vector.
Attack surface
Reached over the network via the upload_log_data interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not detail which endpoint or port, so defenders should treat any network-reachable Cobbler instance as exposed.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.68635 (99.3rd percentile), indicating a high modeled likelihood of exploitation activity. References are limited to the patch commit and the 3.3.0 release, with no public exploit or PoC tags supplied.
What to do
- Upgrade Cobbler to 3.3.0 or later, which contains the fix commit d8f60bbf14a838c8c8a1dba98086b223e35fe70a.
- Restrict network access to the Cobbler service and its XML-RPC/API endpoints to trusted management networks only.
- Run the Cobbler service with a least-privilege account and confine its writable directories to the minimum required paths.
- Monitor and alert on unexpected file creation or modification in Cobbler-managed directories and web-accessible paths.
- If patching is delayed, disable or block the upload_log_data functionality where it is not operationally required.
Detection
- Audit Cobbler logs and web server access logs for calls to upload_log_data, especially from unexpected source addresses.
- Monitor file integrity in Cobbler data, tftpboot, and web root directories for new or modified files outside normal provisioning activity.
- Alert on new executable or script files appearing in paths writable by the Cobbler service account.
- Baseline normal Cobbler API clients and flag upload_log_data requests from hosts that have not previously used the service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/cobbler/cobbler/commit/d8f60bbf14a838c8c8a1dba98086b223e35fe70a | PatchThird Party Advisory |
| https://github.com/cobbler/cobbler/releases/tag/v3.3.0 | ProductThird Party Advisory |
| https://github.com/cobbler/cobbler/commit/d8f60bbf14a838c8c8a1dba98086b223e35fe70a | PatchThird Party Advisory |
| https://github.com/cobbler/cobbler/releases/tag/v3.3.0 | ProductThird Party Advisory |
Track CVE-2021-40324 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40324), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.