Impact
An operating‑system command injection flaw exists in NooBaa’s cluster_internal_api.set_hostname_internal function. The hostname value supplied by an attacker is passed directly to a shell command without sanitization, enabling an authenticated user with administrative privileges to inject shell metacharacters and execute arbitrary commands on the host system with the privileges of the NooBaa process.
Affected Systems
The vulnerability affects Red Hat Openshift Data Foundation 4, specifically the NooBaa core component that manages the Multi‑Cloud Object Gateway. No specific version numbers are listed in the CNA data, so all installed instances of the default 4.x release are considered potentially affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑severity flaw, but the EPSS score is not available and it is not listed in the CISA KEV catalog. The attack requires local administrative authentication, so the likelihood of exploitation depends on the exposure of privileged accounts. If exploited, the attacker can gain host‑level control, leading to full system compromise.
OpenCVE Enrichment