CVE-2013-2121
Foreman (RedHat OpenStack/Satellite) - bookmarks/create Code Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
Vulnerabilidad de inyección Eval en el método "create" en el controlador Bookmarks en Foreman anterior a 1.2.0-RC2, permite a usuarios autenticados remotamente con permisos para crear favoritos, la ejecución arbitraria de código a través de un atributo de nombre de controlador.
A flaw was found in the create method of the Foreman Bookmarks controller. A user with privileges to create a bookmark could use this flaw to execute arbitrary code with the privileges of the user running Foreman, giving them control of the system running Foreman and all systems managed by Foreman.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-06-27 CVE Published
- 2013-07-23 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://projects.theforeman.org/issues/2631 | X_refsource_confirm | |
https://groups.google.com/forum/#%21topic/foreman-users/6WpO_3ugiXU | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/122510 | 2013-07-23 | |
https://www.exploit-db.com/exploits/27045 | 2013-07-23 | |
http://www.exploit-db.com/exploits/27045 | 2024-08-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=966804 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0995.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2013-2121 | 2013-06-27 | |
https://bugzilla.redhat.com/show_bug.cgi?id=968166 | 2013-06-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 3.0 Search vendor "Redhat" for product "Openstack" and version "3.0" | - |
Affected
| ||||||
Theforeman Search vendor "Theforeman" | Foreman Search vendor "Theforeman" for product "Foreman" | <= 1.2.0 Search vendor "Theforeman" for product "Foreman" and version " <= 1.2.0" | rc1 |
Affected
| ||||||
Theforeman Search vendor "Theforeman" | Foreman Search vendor "Theforeman" for product "Foreman" | 1.1 Search vendor "Theforeman" for product "Foreman" and version "1.1" | - |
Affected
|