smart_proxy_dynflow gem authentication bypass in Foreman remote execution feature
Critical severity
GitHub Reviewed
Published
Oct 8, 2018
to the GitHub Advisory Database
•
Updated Aug 28, 2023
Package
Affected versions
= 0.2.0
< 0.1.11
Patched versions
0.2.1
0.1.11
Description
Published by the National Vulnerability Database
Sep 21, 2018
Published to the GitHub Advisory Database
Oct 8, 2018
Reviewed
Jun 16, 2020
Last updated
Aug 28, 2023
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.
References