{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "Arbitrary File Disclosure/Template Injection via generate_script RPC method",
    "tracking": {
      "current_release_date": "2026-08-11T15:00:38+00:00",
      "generator": {
        "date": "2026-08-11T15:00:38+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-40323",
      "initial_release_date": "2021-09-20T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T15:00:38+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8.10.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.2.0.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.2.0.z",
              "product_id": "rhel-8.2.0.z.aus",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_aus:8.2"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.4.0.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.4.0.z",
              "product_id": "rhel-8.4.0.z.eus",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_eus:8.4"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.6.0.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.6.0.z",
              "product_id": "rhel-8.6.0.z.aus",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_aus:8.6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.8.0.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.8.0.z",
              "product_id": "rhel-8.8.0.z.eus",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_eus:8.8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "koan",
            "product": {
              "name": "koan",
              "product_id": "koan",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/koan"
              }
            }
          },
          {
            "category": "product_version",
            "name": "python3-koan",
            "product": {
              "name": "python3-koan",
              "product_id": "python3-koan",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/python3-koan"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhn-tools:1.0/cobbler",
            "product": {
              "name": "rhn-tools:1.0/cobbler",
              "product_id": "rhn-tools:1.0/cobbler.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/cobbler?arch=src&rpmmod=rhn-tools:1.0"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "koan as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8.10.z:koan"
        },
        "product_reference": "koan",
        "relates_to_product_reference": "rhel-8.10.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "koan as a component of Red Hat Enterprise Linux 8.2.0.z",
          "product_id": "rhel-8.2.0.z.aus:koan"
        },
        "product_reference": "koan",
        "relates_to_product_reference": "rhel-8.2.0.z.aus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "koan as a component of Red Hat Enterprise Linux 8.4.0.z",
          "product_id": "rhel-8.4.0.z.eus:koan"
        },
        "product_reference": "koan",
        "relates_to_product_reference": "rhel-8.4.0.z.eus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "koan as a component of Red Hat Enterprise Linux 8.8.0.z",
          "product_id": "rhel-8.8.0.z.eus:koan"
        },
        "product_reference": "koan",
        "relates_to_product_reference": "rhel-8.8.0.z.eus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "koan as a component of Red Hat Enterprise Linux 8.6.0.z",
          "product_id": "rhel-8.6.0.z.aus:koan"
        },
        "product_reference": "koan",
        "relates_to_product_reference": "rhel-8.6.0.z.aus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-koan as a component of Red Hat Enterprise Linux 8.8.0.z",
          "product_id": "rhel-8.8.0.z.eus:python3-koan"
        },
        "product_reference": "python3-koan",
        "relates_to_product_reference": "rhel-8.8.0.z.eus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-koan as a component of Red Hat Enterprise Linux 8.6.0.z",
          "product_id": "rhel-8.6.0.z.aus:python3-koan"
        },
        "product_reference": "python3-koan",
        "relates_to_product_reference": "rhel-8.6.0.z.aus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-koan as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8.10.z:python3-koan"
        },
        "product_reference": "python3-koan",
        "relates_to_product_reference": "rhel-8.10.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-koan as a component of Red Hat Enterprise Linux 8.4.0.z",
          "product_id": "rhel-8.4.0.z.eus:python3-koan"
        },
        "product_reference": "python3-koan",
        "relates_to_product_reference": "rhel-8.4.0.z.eus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-koan as a component of Red Hat Enterprise Linux 8.2.0.z",
          "product_id": "rhel-8.2.0.z.aus:python3-koan"
        },
        "product_reference": "python3-koan",
        "relates_to_product_reference": "rhel-8.2.0.z.aus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhn-tools:1.0/cobbler.src as a component of Red Hat Enterprise Linux 8.6.0.z",
          "product_id": "rhel-8.6.0.z.aus:rhn-tools:1.0/cobbler.src"
        },
        "product_reference": "rhn-tools:1.0/cobbler.src",
        "relates_to_product_reference": "rhel-8.6.0.z.aus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhn-tools:1.0/cobbler.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8.10.z:rhn-tools:1.0/cobbler.src"
        },
        "product_reference": "rhn-tools:1.0/cobbler.src",
        "relates_to_product_reference": "rhel-8.10.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhn-tools:1.0/cobbler.src as a component of Red Hat Enterprise Linux 8.2.0.z",
          "product_id": "rhel-8.2.0.z.aus:rhn-tools:1.0/cobbler.src"
        },
        "product_reference": "rhn-tools:1.0/cobbler.src",
        "relates_to_product_reference": "rhel-8.2.0.z.aus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhn-tools:1.0/cobbler.src as a component of Red Hat Enterprise Linux 8.4.0.z",
          "product_id": "rhel-8.4.0.z.eus:rhn-tools:1.0/cobbler.src"
        },
        "product_reference": "rhn-tools:1.0/cobbler.src",
        "relates_to_product_reference": "rhel-8.4.0.z.eus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhn-tools:1.0/cobbler.src as a component of Red Hat Enterprise Linux 8.8.0.z",
          "product_id": "rhel-8.8.0.z.eus:rhn-tools:1.0/cobbler.src"
        },
        "product_reference": "rhn-tools:1.0/cobbler.src",
        "relates_to_product_reference": "rhel-8.8.0.z.eus"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-40323",
      "cwe": {
        "id": "CWE-200",
        "name": "Exposure of Sensitive Information to an Unauthorized Actor"
      },
      "discovery_date": "2021-09-20T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-8.10.z:koan",
            "rhel-8.10.z:python3-koan",
            "rhel-8.10.z:rhn-tools:1.0/cobbler.src",
            "rhel-8.2.0.z.aus:koan",
            "rhel-8.2.0.z.aus:python3-koan",
            "rhel-8.2.0.z.aus:rhn-tools:1.0/cobbler.src",
            "rhel-8.4.0.z.eus:koan",
            "rhel-8.4.0.z.eus:python3-koan",
            "rhel-8.4.0.z.eus:rhn-tools:1.0/cobbler.src",
            "rhel-8.6.0.z.aus:koan",
            "rhel-8.6.0.z.aus:python3-koan",
            "rhel-8.6.0.z.aus:rhn-tools:1.0/cobbler.src",
            "rhel-8.8.0.z.eus:koan",
            "rhel-8.8.0.z.eus:python3-koan",
            "rhel-8.8.0.z.eus:rhn-tools:1.0/cobbler.src"
          ]
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in cobbler. This flaw lies in the generate_script RPC method, which accepts unsanitized parameters. This flaw allows an attacker to read arbitrary files on the system as root. Further, the attacker could gain arbitrary code execution using template injection against the default Cheetah template engine, leading to the exposure of sensitive information or execution of arbitrary code. The highest threat from this vulnerability is to confidentiality and integrity.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "rhel-8.10.z:koan",
          "rhel-8.10.z:python3-koan",
          "rhel-8.10.z:rhn-tools:1.0/cobbler.src",
          "rhel-8.2.0.z.aus:koan",
          "rhel-8.2.0.z.aus:python3-koan",
          "rhel-8.2.0.z.aus:rhn-tools:1.0/cobbler.src",
          "rhel-8.4.0.z.eus:koan",
          "rhel-8.4.0.z.eus:python3-koan",
          "rhel-8.4.0.z.eus:rhn-tools:1.0/cobbler.src",
          "rhel-8.6.0.z.aus:koan",
          "rhel-8.6.0.z.aus:python3-koan",
          "rhel-8.6.0.z.aus:rhn-tools:1.0/cobbler.src",
          "rhel-8.8.0.z.eus:koan",
          "rhel-8.8.0.z.eus:python3-koan",
          "rhel-8.8.0.z.eus:rhn-tools:1.0/cobbler.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-40323"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40323"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-40323"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL"
          },
          "products": [
            "rhel-8.10.z:koan",
            "rhel-8.10.z:python3-koan",
            "rhel-8.10.z:rhn-tools:1.0/cobbler.src",
            "rhel-8.2.0.z.aus:koan",
            "rhel-8.2.0.z.aus:python3-koan",
            "rhel-8.2.0.z.aus:rhn-tools:1.0/cobbler.src",
            "rhel-8.4.0.z.eus:koan",
            "rhel-8.4.0.z.eus:python3-koan",
            "rhel-8.4.0.z.eus:rhn-tools:1.0/cobbler.src",
            "rhel-8.6.0.z.aus:koan",
            "rhel-8.6.0.z.aus:python3-koan",
            "rhel-8.6.0.z.aus:rhn-tools:1.0/cobbler.src",
            "rhel-8.8.0.z.eus:koan",
            "rhel-8.8.0.z.eus:python3-koan",
            "rhel-8.8.0.z.eus:rhn-tools:1.0/cobbler.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "rhel-8.10.z:koan",
            "rhel-8.10.z:python3-koan",
            "rhel-8.10.z:rhn-tools:1.0/cobbler.src",
            "rhel-8.2.0.z.aus:koan",
            "rhel-8.2.0.z.aus:python3-koan",
            "rhel-8.2.0.z.aus:rhn-tools:1.0/cobbler.src",
            "rhel-8.4.0.z.eus:koan",
            "rhel-8.4.0.z.eus:python3-koan",
            "rhel-8.4.0.z.eus:rhn-tools:1.0/cobbler.src",
            "rhel-8.6.0.z.aus:koan",
            "rhel-8.6.0.z.aus:python3-koan",
            "rhel-8.6.0.z.aus:rhn-tools:1.0/cobbler.src",
            "rhel-8.8.0.z.eus:koan",
            "rhel-8.8.0.z.eus:python3-koan",
            "rhel-8.8.0.z.eus:rhn-tools:1.0/cobbler.src"
          ]
        }
      ],
      "title": "Arbitrary File Disclosure/Template Injection via generate_script RPC method"
    }
  ]
}