REDHAT-BUG-1629063: The foreman vulnerability

Published Sep 14, 2018
·
Updated

A vulnerability was discovered in the Foreman Remote Execution feature, allowing an unauthorized remote attacker to perform arbitrary code execution on managed hosts. The issue affects the component smartproxydynflow 0.1.8 and later (Foreman >= 1.15, Satellite >= 6.3)

Introducing commit:

https://github.com/theforeman/smartproxydynflow/commit/cb7b0b5c9b602f737ab4c6e9fb47c158241cf49c#diff-6dee70f4339cfc3dd8cedfc2a34f14c2

References:

https://bugzilla.redhat.com/showbug.cgi?id=1629003

Affected Software

3 affected components
The Foreman smart_proxy_dynflow>=0.1.8
The Foreman Foreman>=1.15
Red Hat Satellite>=6.3

Event History

Sep 14, 2018
Data Sourced
via Red Hat·06:55 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1629063?

The severity of REDHAT-BUG-1629063 is classified as critical due to the possibility of arbitrary code execution by an unauthorized remote attacker.

2

How do I fix REDHAT-BUG-1629063?

To fix REDHAT-BUG-1629063, update the smart_proxy_dynflow component to a version later than 0.1.8 and ensure your Foreman or Satellite installation is also updated to the recommended versions.

3

Which versions are affected by REDHAT-BUG-1629063?

REDHAT-BUG-1629063 affects smart_proxy_dynflow version 0.1.8 and later, as well as Foreman version 1.15 and later, and Satellite version 6.3 and later.

4

What component is vulnerable in REDHAT-BUG-1629063?

The vulnerable component in REDHAT-BUG-1629063 is the smart_proxy_dynflow feature related to the Foreman Remote Execution.

5

What type of attack is demonstrated by REDHAT-BUG-1629063?

REDHAT-BUG-1629063 demonstrates an arbitrary code execution attack, allowing remote attackers to run malicious code on managed hosts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203