{"id":"GHSA-gx5g-xcxj-cx2w","summary":"smart_proxy_dynflow gem authentication bypass in Foreman remote execution feature","details":"An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.","aliases":["CVE-2018-14643"],"modified":"2024-02-16T08:19:40.437139Z","published":"2018-10-08T23:18:13Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:38:13Z","nvd_published_at":"2018-09-21T13:29:00Z","cwe_ids":["CWE-287"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14643"},{"type":"WEB","url":"https://github.com/theforeman/smart_proxy_dynflow/pull/54"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2733"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2018-14643"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1629063"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14643"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/smart_proxy_dynflow/CVE-2018-14643.yml"},{"type":"PACKAGE","url":"https://github.com/theforeman/smart_proxy_dynflow"}],"affected":[{"package":{"name":"smart_proxy_dynflow","ecosystem":"RubyGems","purl":"pkg:gem/smart_proxy_dynflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.2.0"},{"fixed":"0.2.1"}]}],"versions":["0.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-gx5g-xcxj-cx2w/GHSA-gx5g-xcxj-cx2w.json"}},{"package":{"name":"smart_proxy_dynflow","ecosystem":"RubyGems","purl":"pkg:gem/smart_proxy_dynflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.11"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.1.0","0.1.1","0.1.10","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-gx5g-xcxj-cx2w/GHSA-gx5g-xcxj-cx2w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}