Red Hat Bugzilla – Bug 1105369
CVE-2014-0007 foreman-proxy: smart-proxy remote command injection
Last modified: 2016-04-26 15:17:28 EDT
Lukas Zap of Red Hat reports: The smart proxy contains a check in tftp.rb to ensure that a specific web URL exists and is valid, this check is vulnerable to a command injection vulnerability.
Public via: http://projects.theforeman.org/issues/6086
Acknowledgements: This issue was discovered by Lukas Zapletal of Red Hat.
This issue has been addressed in following products: OpenStack 4 for RHEL 6 OpenStack 3 for RHEL 6 Via RHSA-2014:0770 https://rhn.redhat.com/errata/RHSA-2014-0770.html