A flaw was found in Cobbler. Arbitrary file write could be achieved via upload_log_data XMLRPC function. References: https://lists.suse.com/pipermail/sle-security-updates/2021-September/009468.html https://github.com/cobbler/cobbler/issues/2795 https://github.com/cobbler/cobbler/pull/2794
Created cobbler tracking bugs for this issue: Affects: epel-7 [bug 2006903] Affects: fedora-all [bug 2006902]