Fedora Account System
Red Hat Associate
Red Hat Customer
Description OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks within Red Hat Satellite (Foreman). The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths. Impact Exploitation allows a restricted user to escalate privileges to the foreman account and execute arbitrary commands . This grants control over the Satellite database and configurations, enabling lateral movement and full root Remote Code Execution on all managed hosts (as demonstrated in F-03 Command Injection in foreman-rake errors:fetch_log via request_id Parameter). Recommendations Validate Input: Implement strict validation for both the destination and file parameters in the Rake tasks to ensure they only contain valid filesystem paths and no shell metacharacters before processing. Use Argument Arrays: Modify the underlying code to use non-shell execution methods (e.g., passing arguments as an array to system() or exec()) to prevent shell interpretation.