CVE-2013-4386

Redhat Openstack < 1.2.2 - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.

References (3)

Core 3
Core References
Patch x_refsource_confirm
http://projects.theforeman.org/issues/3160
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1522.html

Scores

EPSS 0.0124
EPSS Percentile 66.1%

Details

CWE
CWE-89
Status published
Products (4)
redhat/openstack 3.0
theforeman/foreman 1.2.0 (3 CPE variants)
theforeman/foreman 1.2.1
theforeman/foreman < 1.2.2
Published Nov 20, 2013
Tracked Since Feb 18, 2026