Описание
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
Отчет
Successful exploitation of this issue allows a restricted user to escalate privileges to the foreman account and execute arbitrary commands. This grants control over the Satellite database and configurations, enabling lateral movement and full root remote code execution on all managed hosts.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Satellite 6 | satellite:el8/foreman | Affected | ||
| Red Hat Satellite 6.16 for RHEL 8 | foreman | Fixed | RHSA-2026:74506 | 01.10.2026 |
| Red Hat Satellite 6.16 for RHEL 9 | foreman | Fixed | RHSA-2026:74506 | 01.10.2026 |
| Red Hat Satellite 6.18 for RHEL 9 | foreman | Fixed | RHSA-2026:74504 | 01.10.2026 |
| Red Hat Satellite 6.19 for RHEL 9 | foreman | Fixed | RHSA-2026:74503 | 01.10.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
A flaw was found in Foreman. OS command injection vulnerabilities exis ...
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
EPSS
8.2 High
CVSS3