Actions
Bug #36759
closedCVE-2022-3874: OS command injection via ct_command and fcct_command
Difficulty:
Triaged:
No
Bugzilla link:
Description
the ct_command and fcct_command settings allow authenticated users to execute arbitrary commands on the server. These commands are used to transpile CoreOS and Fedora CoreOS configurations in templates. Changing the command requires admin privileges on the Foreman instance.
Updated by The Foreman Bot over 1 year ago
- Status changed from New to Ready For Testing
- Pull request https://github.com/theforeman/foreman/pull/9836 added
Updated by The Foreman Bot about 1 year ago
- Pull request https://github.com/theforeman/foreman/pull/9845 added
Updated by Evgeni Golov about 1 year ago
- Status changed from Ready For Testing to Closed
Applied in changeset foreman|d430f3fb71485c12723c3d883b9c5064fbccb477.
Updated by Evgeni Golov about 1 year ago
- Related to Bug #36812: allow setting (fc)ct_location added
Actions