A server side remote code execution vulnerability was...
High severity
Unreviewed
Published
Dec 24, 2021
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Dec 23, 2021
Published to the GitHub Advisory Database
Dec 24, 2021
Last updated
Feb 3, 2023
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.
References