Red Hat Satellite
cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*, +1 more
- 6.16.5.2
A command injection vulnerability has been identified in the Foreman component of Red Hat Satellite. This issue allows authenticated users with edit_settings permissions to execute arbitrary commands on the underlying operating system. The vulnerability arises from inadequate server-side validation of command whitelisting, as the existing whitelist for CoreOS Transpiler Command and Fedora CoreOS Transpiler Command is only enforced on the client-side.
Exploitation of this vulnerability could lead to unauthorized execution of operating system commands, allowing attackers to disable the product or manipulate data beyond their direct access rights. Since the commands are executed in the context of the application, any malicious actions could be attributed to the application or its owner.
To reproduce this vulnerability, an authenticated user with edit_settings permissions can modify the ct_location and fcct_location parameters in Red Hat Satellite 6.16.5.2. The absence of proper server-side validation allows these parameters to bypass the implemented whitelist, enabling arbitrary command execution on the operating system.
Users are advised to upgrade to Red Hat Satellite 6.18 for RHEL 9, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.