Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. (CVE-2021-40324) | HOL Guard CVE