Fedora Account System
Red Hat Associate
Red Hat Customer
Description The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a Multi-Stage Execution Chain that allows for both Server-Side Template Injection (SSTI) and Insecure Deserialization. The vulnerability execution chain has two stages: Template Injection (ERB): The first stage uses ERB.new(...).result. This evaluates the file as a Ruby template. Any code inside <%= ... %> is executed by the Ruby interpreter to generate a string. This is an SSTI that allows for direct OS command injection. Insecure Deserialization (YAML): The second stage takes the rendered string and passes it to YAML.load. Because this is an unsafe parser, it allows for object injection. Even if an attacker cannot use ERB tags, they can craft YAML that instantiates malicious Ruby "gadget chains" to achieve code execution. The vulnerability exists in two different application functionalities, thus it can be exploited in two different ways: Primary config: SETTINGS.merge! YAML.load(ERB.new(File.read(settings_file)).result) allows an attacker to craft a malicious /etc/foreman-maintain/foreman_maintain.yml file that will be loaded and executed by foreman-rake on start. Plugins config: SETTINGS.merge! YAML.load(ERB.new(File.read(f)).result) allows an attacker to craft a malicious file that will be executed from /usr/share/foreman/config/settings.plugins.d/ by foreman-rake on start. Impact Indirect Triggering & Privileged RCE: foreman-rake exposes underlying execution primitives that higher-level orchestration tools (like foreman-maintain or foreman-installer) rely on to interact with the application. Because these tools implicitly pass commands down, the vulnerability can be triggered indirectly during routine administrative operations, resulting in Remote Code Execution (RCE) in a high-trust context (often foreman or root). Total Infrastructure Compromise: Compromising the management plane (Satellite server) allows an attacker to pivot and execute arbitrary code across all Satellite Managed Hosts. Supply Chain Risk: While direct local exploitation requires prior root access, this flaw presents a critical supply chain risk. An adversary could distribute malicious plugins or compromised configuration files through public repositories (e.g., RubyGems, GitHub). Note: The CVSS vector and severity are based on this supply chain attack vector. RECOMMENDATIONS Replace YAML.load with YAML.safe_load(content, permitted_classes: [Symbol]) in both locations in settings.rb. Remove the ERB.new().result evaluation. Configuration files must be treated as static data, never as executable templates.