CVE-2021-40323: cobbler: Arbitrary File Disclosure/Template Injection via generate_script RPC method

Severity: Critical

CVSS Score: 9.8

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.