10
CVSSv2

CVE-2018-14643

Published: 21/09/2018 Updated: 12/02/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman -

Vendor Advisories

Synopsis Critical: rubygem-smart_proxy_dynflow security update Type/Severity Security Advisory: Critical Topic An update for rubygem-smart_proxy_dynflow is now available for Red Hat Satellite 63 for RHEL 7Red Hat Product Security has rated this update as having a security impact of Critical A Common Vuln ...
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context ...