#VU78931 OS Command Injection in Foreman - CVE-2023-0118
Published: August 3, 2023
Foreman
Foreman
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing templates . A remote privileged user can bypass safe mode and inject and execute arbitrary OS commands via the Report Templates function by modifying the "template" JSON value in the POST request.