Launchpad.net

CVE 2021-40323

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

See the CVE page on Mitre.org for more details.