Back to bug 2140577

Who When What Removed Added
RaTasha Tillery-Smith 2022-11-07 14:43:16 UTC CC security-response-team
Alias CVE-2022-3874
Summary EMBARGOED foreman: OS command injection via ct_command and fcct_command EMBARGOED CVE-2022-3874 foreman: OS command injection via ct_command and fcct_command
Deadline 2022-11-22
Doc Text A command injection flaw was found in foreman. An authenticated user with admin privileges on the foreman instance can transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system. A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system.
Avinash Hanwate 2022-11-09 11:53:12 UTC Depends On 2141267
Yadnyawalk Tale 2023-01-24 06:08:54 UTC Deadline 2022-11-22 2022-12-07
Depends On 2144841
Depends On 2144846
Deadline 2022-12-07
CC egolov, ytale
Doc Type --- If docs needed, set a value
Red Hat Bugzilla 2023-03-02 08:27:53 UTC Blocks 2162363
Depends On 2163695, 2163694
CC myarboro
Red Hat Bugzilla 2023-05-15 20:19:04 UTC Deadline 2023-04-19
Summary EMBARGOED CVE-2022-3874 foreman: OS command injection via ct_command and fcct_command CVE-2022-3874 foreman: OS command injection via ct_command and fcct_command
CC myarboro
Group security, qe_staff
Deadline 2023-04-19
CC btotty
Red Hat Bugzilla 2023-07-07 08:34:11 UTC Assignee security-response-team nobody
CC security-response-team

Back to bug 2140577