First published: Sun Jan 22 2023(Updated: )
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Theforeman Foreman | <3.8.0 | |
Redhat Satellite | >=6.0 | |
redhat/foreman | <3.8.0 | 3.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0462 is an arbitrary code execution flaw in Foreman that allows an admin user to execute arbitrary code on the underlying operating system.
The severity of CVE-2023-0462 is critical, with a CVSS score of 9.1.
CVE-2023-0462 affects Foreman versions up to 3.8.0 and allows an admin user to execute arbitrary code.
CVE-2023-0462 affects Red Hat Satellite versions from 6.0 and allows an admin user to execute arbitrary code.
To fix CVE-2023-0462, update Foreman to a version beyond 3.8.0 or update Red Hat Satellite to a version beyond 6.0.