Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/cobbler/cobbler/commit/d8f60bbf14a838c8c8a1dba98086b223e35fe70a | third party advisory patch |
https://github.com/cobbler/cobbler/releases/tag/v3.3.0 | third party advisory product |