Cobbler before 3.3.0 allows authorization bypass for modification of settings. (CVE-2021-40325) | HOL Guard CVE