Actions
Bug #36759
closedCVE-2022-3874: OS command injection via ct_command and fcct_command
Difficulty:
Triaged:
No
Bugzilla link:
Description
the ct_command and fcct_command settings allow authenticated users to execute arbitrary commands on the server. These commands are used to transpile CoreOS and Fedora CoreOS configurations in templates. Changing the command requires admin privileges on the Foreman instance.
Actions