CVE Vulnerabilities

CVE-2014-0007

Published: Jun 20, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.

Affected Software

Name Vendor Start Version End Version
Foreman Theforeman * 1.4.4 (including)
Foreman Theforeman 1.4.0 (including) 1.4.0 (including)
Foreman Theforeman 1.4.1 (including) 1.4.1 (including)
Foreman Theforeman 1.4.2 (including) 1.4.2 (including)
Foreman Theforeman 1.4.3 (including) 1.4.3 (including)
Foreman Theforeman 1.5.0 (including) 1.5.0 (including)

References