CVE-2013-0171
Foreman < 1.0 - Remote Code Execution via YAML Object in Fact or Report Import API
Title source: llmDescription
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
References (2)
Core 2
Core References
Issue Tracking x_refsource_confirm
http://projects.theforeman.org/issues/2069
Vendor Advisory x_refsource_confirm
http://theforeman.org/security.html
Scores
EPSS
0.0297
EPSS Percentile
85.6%
Details
CWE
CWE-94
Status
published
Products (1)
theforeman/foreman
< 1.0
Published
May 08, 2014
Tracked Since
Feb 18, 2026