CVE-2013-0210: Code Injection
Published May 8, 2014
·Updated
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
Affected Software
6 affected components
theforeman foreman<=1.0
theforeman foreman=0.1
theforeman foreman=0.2
theforeman foreman=0.3
theforeman foreman=0.4
theforeman foreman=0.4.1
Event History
May 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0210?
CVE-2013-0210 is considered critical due to the potential for remote command execution.
2
How do I fix CVE-2013-0210?
To fix CVE-2013-0210, upgrade to Foreman version 1.2.0 or later.
3
What software versions are affected by CVE-2013-0210?
CVE-2013-0210 affects Foreman versions prior to 1.2.0, including 0.1 through 0.4.1.
4
What types of attacks are possible with CVE-2013-0210?
CVE-2013-0210 allows remote attackers to execute arbitrary commands on the affected system.
5
Is there a patch for CVE-2013-0210?
Yes, the patch for CVE-2013-0210 is included in Foreman version 1.2.0 and later.