Fedora Account System
Red Hat Associate
Red Hat Customer
Description A command injection vulnerability exists in the foreman-rake errors:fetch_log task within Red Hat Satellite. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code. Impact Successful exploitation allows a restricted user to escalate privileges to the foreman user and subsequently to root across all managed hosts, Organizations, and Locations. This represents a complete compromise of the Red Hat Satellite server and the entire infrastructure it manages. Recommendations Validate Input: Sanitize the request_id parameter to ensure it only contains alphanumeric characters and dashes, rejecting any input containing shell metacharacters. Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation (e.g., using Open3.capture3 with separate arguments in Ruby). Specifically, the following code in lib/tasks/errors.rake file should be replaced with something like this: -------------------------------------------------------------------------------- // Vulnerable code result = `grep "#{request_id}" "#{file_path}"`