CVE-2013-0171: Code Injection
Published May 8, 2014
·Updated
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
Affected Software
1 affected component
theforeman foreman<=1.0
Event History
May 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0171?
CVE-2013-0171 has been classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2013-0171?
To remediate CVE-2013-0171, upgrade to Foreman version 1.1 or higher.
3
What versions are affected by CVE-2013-0171?
CVE-2013-0171 affects all versions of Foreman prior to 1.1.
4
What type of attack does CVE-2013-0171 enable?
CVE-2013-0171 allows remote attackers to execute arbitrary code via crafted YAML objects in specific APIs.
5
Does CVE-2013-0171 require user interaction?
CVE-2013-0171 does not require user interaction, allowing for exploit without any user involvement.