An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-12516 An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 10 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat satellite Utils
CPEs cpe:/a:redhat:satellite_utils:6.11::el7
cpe:/a:redhat:satellite_utils:6.11::el8
cpe:/a:redhat:satellite_utils:6.12::el8
cpe:/a:redhat:satellite_utils:6.13::el8
Vendors & Products Redhat satellite Utils

Tue, 24 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-09-24T15:05:20.612Z

Reserved: 2023-01-24T12:05:40.039Z

Link: CVE-2023-0462

cve-icon Vulnrichment

Updated: 2024-08-02T05:10:56.254Z

cve-icon NVD

Status : Modified

Published: 2023-09-20T14:15:12.990

Modified: 2024-11-21T07:37:13.563

Link: CVE-2023-0462

cve-icon Redhat

Severity : Important

Publid Date: 2023-03-21T00:00:00Z

Links: CVE-2023-0462 - Bugzilla

cve-icon OpenCVE Enrichment

No data.