First published: Fri Apr 04 2014(Updated: )
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Foreman | <=1.0 | |
Foreman | =0.1 | |
Foreman | =0.2 | |
Foreman | =0.3 | |
Foreman | =0.4 | |
Foreman | =0.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5648 is considered a high severity vulnerability due to the potential for remote SQL command execution.
To fix CVE-2012-5648, update Foreman to version 1.0.2 or later.
CVE-2012-5648 allows remote attackers to perform SQL injection attacks, which can lead to unauthorized data access or manipulation.
Versions of Foreman prior to 1.0.2, including 0.1 to 0.4.1, are affected by CVE-2012-5648.
CVE-2012-5648 is a remote vulnerability, allowing attackers to exploit it over the network without local access.