Lukas Zap of Red Hat reports: The smart proxy contains a check in tftp.rb to ensure that a specific web URL exists and is valid, this check is vulnerable to a command injection vulnerability.
Public via: http://projects.theforeman.org/issues/6086
Acknowledgements: This issue was discovered by Lukas Zapletal of Red Hat.
This issue has been addressed in following products: OpenStack 4 for RHEL 6 OpenStack 3 for RHEL 6 Via RHSA-2014:0770 https://rhn.redhat.com/errata/RHSA-2014-0770.html