CVE-2016-3728

Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:theforeman:foreman:1.11.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.11.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.11.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.11.0:rc3:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.11.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:theforeman:foreman:1.10.3:*:*:*:*:*:*:*

History

12 Feb 2023, 23:20

Type Values Removed Values Added
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1333378', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1333378', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-3728', 'name': 'https://access.redhat.com/security/cve/CVE-2016-3728', 'tags': [], 'refsource': 'MISC'}
Summary It was found that the “variant” parameter in the TFTP API of Foreman was passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary code with the privileges of the Foreman user. Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/.

02 Feb 2023, 21:16

Type Values Removed Values Added
Summary Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/. It was found that the “variant” parameter in the TFTP API of Foreman was passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary code with the privileges of the Foreman user.
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1333378 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-3728 -

Information

Published : 2016-05-20 14:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-3728

Mitre link : CVE-2016-3728

CVE.ORG link : CVE-2016-3728


JSON object : View

Products Affected

theforeman

  • foreman
CWE
CWE-284

Improper Access Control