Fedora Account System
Red Hat Associate
Red Hat Customer
Description The foreman-tail utility in Red Hat Satellite is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands. Impact Successful exploitation allows a local attacker to escape restricted shells and execute arbitrary commands on the Satellite server. Consequently, the attacker could access sensitive information that could lead to remote code execution (RCE) and lateral movement across the managed infrastructure. Recommendations Refactor the script: Remove the use of eval. Use native shell array expansion or find to locate the necessary log files safely. Input Validation: Implement a strict allow-list to ensure only valid service names are processed.