CVE-2023-0462 Vulnerability Details

  /     /     /  

CVE-2023-0462 Metadata Quick Info

CVE Published: 20/09/2023 | CVE Updated: 24/09/2024 | CVE Year: 2023
Source: redhat | Vendor: n/a | Product: foreman
Status : PUBLISHED

CVE-2023-0462 Description

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-94
CWE Name: Improper Control of Generation of Code ( Code Injection )
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).