Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-2121Code Injection in Foreman

Severity
6.0MEDIUMNVD
EPSS
60.9%
top 1.69%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 31
Latest updateMay 14

Description

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-j6g9-xm4c-vp6v: Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 12022-05-14
CVEList
CVE-2013-2121: Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 12013-07-31

💥Exploits & PoCs

1
Exploit-DB
Foreman (RedHat OpenStack/Satellite) - bookmarks/create Code Injection (Metasploit)2013-07-23

📋Vendor Advisories

1
Red Hat
Foreman: app/controllers/bookmarks_controller.rb remote code execution2013-06-07

💬Community

1
Bugzilla
CVE-2013-2121 Foreman: app/controllers/bookmarks_controller.rb remote code execution2013-05-29
CVE-2013-2121 — Code Injection in Theforeman Foreman | cvebase