GHSA-79jg-9wx4-f5rrMediumCVSS 5.3
A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-12542
- https://access.redhat.com/errata/RHSA-2026:74503
- https://access.redhat.com/security/cve/CVE-2026-12542
- https://bugzilla.redhat.com/show_bug.cgi?id=2489971
- https://access.redhat.com/errata/RHSA-2026:74504
- https://access.redhat.com/errata/RHSA-2026:74506
- https://access.redhat.com/errata/RHSA-2026:74505
- https://github.com/advisories/GHSA-79jg-9wx4-f5rr