REDHAT-BUG-1629063: The foreman vulnerability
A vulnerability was discovered in the Foreman Remote Execution feature, allowing an unauthorized remote attacker to perform arbitrary code execution on managed hosts. The issue affects the component smartproxydynflow 0.1.8 and later (Foreman >= 1.15, Satellite >= 6.3)
Introducing commit:
https://github.com/theforeman/smartproxydynflow/commit/cb7b0b5c9b602f737ab4c6e9fb47c158241cf49c#diff-6dee70f4339cfc3dd8cedfc2a34f14c2
References:
https://bugzilla.redhat.com/showbug.cgi?id=1629003
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1629063?
The severity of REDHAT-BUG-1629063 is classified as critical due to the possibility of arbitrary code execution by an unauthorized remote attacker.
How do I fix REDHAT-BUG-1629063?
To fix REDHAT-BUG-1629063, update the smart_proxy_dynflow component to a version later than 0.1.8 and ensure your Foreman or Satellite installation is also updated to the recommended versions.
Which versions are affected by REDHAT-BUG-1629063?
REDHAT-BUG-1629063 affects smart_proxy_dynflow version 0.1.8 and later, as well as Foreman version 1.15 and later, and Satellite version 6.3 and later.
What component is vulnerable in REDHAT-BUG-1629063?
The vulnerable component in REDHAT-BUG-1629063 is the smart_proxy_dynflow feature related to the Foreman Remote Execution.
What type of attack is demonstrated by REDHAT-BUG-1629063?
REDHAT-BUG-1629063 demonstrates an arbitrary code execution attack, allowing remote attackers to run malicious code on managed hosts.