Fedora Account System
Red Hat Associate
Red Hat Customer
Description A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &). The following files are affected: lib/hammer_cli/utils.rb - open_in_editor method executes: -------------------------------------------------------------------------------- system("#{ENV['EDITOR'] || 'vi'} #{f.path}") -------------------------------------------------------------------------------- railties-7.0.10 , specifically railties-7.0.10/lib/rails/commands/encrypted/encrypted_command.rb and railties-7.0.10/lib/rails/commands/secrets/secrets_command.rb, the framework handles interactive editing via: -------------------------------------------------------------------------------- system("#{ENV["EDITOR"]} #{tmp_path}") -------------------------------------------------------------------------------- Impact This flaw allows a local attacker to execute arbitrary commands within the tool's effective security context. If the utility is run with elevated permissions (e.g., via sudo) while preserving the environment, this leads to root-level privilege escalation. Recommendations Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation Consider updating/upgrading Railties: the version in use (7.0.10) is End-of-Life (EOL). This means the core framework underlying the application will not receive official security patches for this flaw, necessitating manual remediation by the Satellite/Foreman engineering teams or a version upgrade (fixed in the latest version).