An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | centos-upgrade-foreman-clicentos-upgrade-satellitecentos-upgrade-satellite-brandingcentos-upgrade-satellite-cli | Nov 1, 2023 | Sep 20, 2023 |
| Redhat_linux | — | redhat-upgrade-foreman-cliredhat-upgrade-rubygem-foreman_maintainredhat-upgrade-satelliteredhat-upgrade-satellite-brandingredhat-upgrade-satellite-cli | Nov 1, 2023 | Sep 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub