An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
2023-09-20T14:15:12.990
2024-11-21T07:37:13.563
Modified
CVSSv3.1: 8.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | theforeman | foreman | < 3.8.0 | Yes |
Application | redhat | satellite | ≥ 6.0 | Yes |