CVE-2023-0462

HIGH

Foreman < 3.8.0 - Authenticated Remote Code Execution via YAML Global Parameter Injection

Title source: llm
STIX 2.1

Description

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2023-0462
Issue Tracking, Third Party Advisory issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2162970

Scores

CVSS v3 8.0
EPSS 0.0009
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
redhat/satellite 6.0
theforeman/foreman < 3.8.0
Published Sep 20, 2023
Tracked Since Feb 18, 2026