Red Hat Bugzilla – Bug 988644
CVE-2013-4172 CFME 2.0 web interface: Ruby code injection
Last modified: 2013-12-11 09:57:39 EST
James Laska (jlaska@redhat.com) reports: While filing an upstream bug regarding CFME not sanitizing user-input, I discovered it is possible to remotely inject ruby code.
Acknowledgements: This issue was discovered by James Laska of Red Hat.
This issue has been addressed in following products: Via RHSA-2013:1157 https://rhn.redhat.com/errata/RHSA-2013-1157.html