REDHAT-BUG-2304090: Command Injection
A command injection vulnerability was identified in Foreman, affecting the "Host Init Config" template. The issue arises when commands are injected through the "Install Packages" field on the "Register Host" page. An attacker with elevated privileges on the Foreman server could craft malicious commands, which would be executed when the host is registered. This could lead to unauthorized actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2304090?
The severity of REDHAT-BUG-2304090 is categorized as high due to the command injection vulnerability.
How do I fix REDHAT-BUG-2304090?
To fix REDHAT-BUG-2304090, apply the latest security patches provided by Red Hat for Foreman.
What software is affected by REDHAT-BUG-2304090?
The affected software for REDHAT-BUG-2304090 is the Foreman application.
Who can exploit REDHAT-BUG-2304090?
An attacker with elevated privileges on the Foreman server can exploit REDHAT-BUG-2304090.
What specific feature in Foreman is impacted by REDHAT-BUG-2304090?
The 'Install Packages' field on the 'Register Host' page in Foreman is impacted by REDHAT-BUG-2304090.