CVE Vulnerabilities

CVE-2014-0007

Published: Jun 20, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
10 CRITICAL
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu

The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.

Affected Software

Name Vendor Start Version End Version
Foreman Theforeman * 1.4.4 (including)
Foreman Theforeman 1.4.0 (including) 1.4.0 (including)
Foreman Theforeman 1.4.1 (including) 1.4.1 (including)
Foreman Theforeman 1.4.2 (including) 1.4.2 (including)
Foreman Theforeman 1.4.3 (including) 1.4.3 (including)
Foreman Theforeman 1.5.0 (including) 1.5.0 (including)
OpenStack 3 for RHEL 6 RedHat ruby193-foreman-proxy-0:1.1.10001-7.el6ost *
OpenStack 4 for RHEL 6 RedHat foreman-proxy-0:1.3.0-5.el6sat *
Red Hat Satellite 6.0 RedHat foreman-proxy-0:1.6.0.30-1.el7sat *
Red Hat Satellite 6.0 RedHat foreman-proxy-0:1.6.0.30-1.el7sat *

References