CVE-2022-3874
Summary
| CVE | CVE-2022-3874 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-22 14:15:00 UTC |
| Updated | 2023-11-07 03:51:00 UTC |
| Description | A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 242230 Red Hat Update for Satellite 6.12.5.2 (RHSA-2023:5979)
- 242347 Red Hat Update for Satellite 6.14 (RHSA-2023:6818)
- 242363 Red Hat Update for Satellite 6.13.5 (RHSA-2023:5931)
- 6000042 Debian Security Update for libreoffice (DLA 3526-1)
- 961065 Rocky Linux Security Update for Satellite (RLSA-2023:6818)