Project

General

Profile

Actions

Bug #36759

closed

CVE-2022-3874: OS command injection via ct_command and fcct_command

Added by Evgeni Golov 10 months ago. Updated 9 months ago.

Status:
Closed
Priority:
High
Assignee:
Category:
Settings
Target version:
Fixed in Releases:
Found in Releases:

Description

the ct_command and fcct_command settings allow authenticated users to execute arbitrary commands on the server. These commands are used to transpile CoreOS and Fedora CoreOS configurations in templates. Changing the command requires admin privileges on the Foreman instance.


Related issues 1 (0 open1 closed)

Related to Installer - Bug #36812: allow setting (fc)ct_locationClosedEvgeni GolovActions
Actions

Also available in: Atom PDF