HIGH
foreman-proxy: smart-proxy remote command injection
Published Jun 20, 2014
7.5
HIGHCVSS 2.0
EPSS 9.02%
Description
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
Affected products
No data.
OR
- ≤ 1.4.4
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.5.0
No data.
OpenStack 3 for RHEL 6
ruby193-foreman-proxy-0:1.1.10001-7.el6ost
Fixed · RHSA-2014:0770
OpenStack 4 for RHEL 6
foreman-proxy-0:1.3.0-5.el6sat
Fixed · RHSA-2014:0770
Red Hat Satellite 6.0
foreman-proxy-0:1.6.0.30-1.el6sat
Fixed · RHEA-2014:1175
Red Hat Satellite 6.0
foreman-proxy-0:1.6.0.30-1.el6sat
Fixed · RHEA-2014:1175
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)
foreman-proxy
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | ruby193-foreman-proxy-0:1.1.10001-7.el6ost | Fixed | RHSA-2014:0770 |
| OpenStack 4 for RHEL 6 | foreman-proxy-0:1.3.0-5.el6sat | Fixed | RHSA-2014:0770 |
| Red Hat Satellite 6.0 | foreman-proxy-0:1.6.0.30-1.el6sat | Fixed | RHEA-2014:1175 |
| Red Hat Satellite 6.0 | foreman-proxy-0:1.6.0.30-1.el6sat | Fixed | RHEA-2014:1175 |
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | foreman-proxy | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://projects.theforeman.org/issues/6086 x_refsource_CONFIRMPatch
- http://rhn.redhat.com/errata/RHSA-2014-0770.html vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2014-0007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1105369 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0111 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0007
- https://www.cve.org/CVERecord?id=CVE-2014-0007
| Link | Providers | Tags |
|---|---|---|
| http://projects.theforeman.org/issues/6086 | x_refsource_CONFIRMPatch | |
| http://rhn.redhat.com/errata/RHSA-2014-0770.html | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2014-0007 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1105369 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0111 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-0007 | ||
| https://www.cve.org/CVERecord?id=CVE-2014-0007 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 20, 2014
Updated Aug 6, 2024
Reserved Dec 3, 2013
Link CVE-2014-0007
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2014-0111 Assigner redhat
Published Jun 20, 2014
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2014-0111