#VU82279 OS Command Injection in Red Hat Satellite - CVE-2022-3874
Published: October 20, 2023
Red Hat Satellite
Red Hat Inc.
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing CoreOS and Fedora CoreOS configurations in templates in foreman. A remote user with administrative privileges can inject arbitrary OS commands into configuration templates and execute them on the system.