CVE-2013-4386: SQL Injection
Published Nov 19, 2013
·Updated
Multiple SQL injection vulnerabilities in app/models/concerns/hostcommon.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
Affected Software
6 affected components
redhat Openstack=3.0
theforeman foreman<=1.2.2
theforeman foreman=1.2.0
theforeman foreman=1.2.0-rc1
theforeman foreman=1.2.0-rc2
theforeman foreman=1.2.1
Remediation
Patch Available
Event History
Nov 19, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4386?
CVE-2013-4386 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2013-4386?
To fix CVE-2013-4386, you should upgrade to Foreman version 1.2.3 or later.
3
What vulnerabilities does CVE-2013-4386 exploit?
CVE-2013-4386 exploits multiple SQL injection vulnerabilities via the fqdn or hostgroup parameters.
4
Which versions of Foreman are affected by CVE-2013-4386?
CVE-2013-4386 affects Foreman versions up to and including 1.2.2.
5
Can CVE-2013-4386 impact my OpenStack deployment?
Yes, CVE-2013-4386 can impact OpenStack deployments using vulnerable versions of Foreman.