Arbitrary Ruby code execution via Discovery setting
|Assigned To:||Alon Goldboim|
|Target version:||Plugin 5.0.2|
|Velocity based estimate||-|
We have couple of evals during review of new Discovery Show page:
You can run arbitrary Ruby code by entering it on the About - Settings - Discovery and then visiting a discovered host detail page where it gets rendered.
#3 Updated by Dominic Cleal about 1 year ago
- Private changed from Yes to No
Marking as public as it's been referenced in the associated pull request.
Lukas has also reported it to foreman-security and since this only affects the version of Discovery that's used with a release candidate version of Foreman, no CVE will be assigned as it's generally pre-release. The issue should be resolved in time for 1.11.0's release and it should be documented on http://theforeman.org/security.html.