CVE-2023-0462

critical

Description

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.

References

https://bugzilla.redhat.com/show_bug.cgi?id=2162970

https://access.redhat.com/security/cve/CVE-2023-0462

Details

Source: Mitre, NVD

Published: 2023-09-20

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Severity: Critical