Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0462


An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.


Published

2023-09-20T14:15:12.990

Last Modified

2024-11-21T07:37:13.563

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application theforeman foreman < 3.8.0 Yes
Application redhat satellite ≥ 6.0 Yes

References