An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HRed Hat Satellite
APPRedhat≥ 6.0Theforeman Foreman
APPTheforeman< 3.8.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
CVE-2024-7923CRITICAL9.8PL ✓same product
Authentication bypass w Pulpcore/Red Hat Satellite przez nagłówek HTTP
CVE-2024-7012CRITICAL9.8PL ✓same product
Authentication Bypass w Foreman/Red Hat Satellite via zniekształcony nagłówek HTTP
CVE-2023-0118CRITICAL9.1PL ✓same product
Arbitrary code execution w Foreman — obejście safe mode w szablonach