HomeRedhatCVE-2022-3874

CVE-2022-3874

HIGH
8.0CVSS
Published: 2023-09-22
Updated: 2024-11-21
AI Analysis

Description

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
network
Complexity
high
Privileges
high
User Action
none
Scope
changed
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-78CWE-78

Metadata

Primary Vendor
REDHAT
Published
9/22/2023
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

redhat : satellitetheforeman : foreman

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2022-3874 | HIGH Severity | CVEDatabase.com | CVEDatabase.com