HTTP: Foreman bookmarks_controller.rb Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Foreman. Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the user running the application.

Extended Description

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.

Affected Products

Redhat openstack

References

BugTraq: 60833

CVE: CVE-2013-2121

Short Name
HTTP:MISC:FOREMAN-BOOKMARKS-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2013-2121 Code Execution Foreman Remote bid:60833 bookmarks_controller.rb
Release Date
10/10/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3571
False Positive
Unknown
Vendors

Theforeman

Redhat

CVSS Score

6.0

Found a potential security threat?