Description
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
References (3)
Core 3
Core References
Mailing List x_refsource_confirm
https://groups.google.com/forum/#%21topic/foreman-announce/GKMNXM66Z84
Patch x_refsource_confirm
http://projects.theforeman.org/issues/3160
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1522.html
Scores
EPSS
0.0124
EPSS Percentile
66.1%
Details
CWE
CWE-89
Status
published
Products (4)
redhat/openstack
3.0
theforeman/foreman
1.2.0 (3 CPE variants)
theforeman/foreman
1.2.1
theforeman/foreman
< 1.2.2
Published
Nov 20, 2013
Tracked Since
Feb 18, 2026