REDHAT-BUG-2534185: Foreman Foreman vulnerability
A Safemode bypass attack has been identified that exposes a number of weaknesses in Foreman leading to low-privilege (i.e. minimum "view" permissions) to be able to perform limited Remote Code Execution (RCE). It appears that a copy of the delegatemethods to the local scope allows an adversary to append eval to the permitted methods list leveraged by safemode, thus permitting RCE through the templating engine.