在 rubygem-hammer_cli 中发现了一个漏洞。由于将 $EDITOR 环境变量不安全地插入到 Ruby 的 system() 方法中,Hammer CLI 以及随 Satellite 分发的 Railties(Ruby on Rails)组件中存在命令注入漏洞。通过向 system() 传递单个经过插值的字符串,应用程序会调用系统 shell(/bin/sh),该 shell 会解释执行 shell 元字符(例如 ;、
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | any |
affected |
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0-2.el8sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0-2.el9sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0-2.el9sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0-2.el9sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0-2.el9sat< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0-2.el8sat ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0-2.el9sat ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0-2.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0-2.el9sat ~ * |
cpe:/a:redhat:satellite:6.18::el9
|
|
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0-2.el9sat ~ * |
cpe:/a:redhat:satellite:6.19::el9
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96658 | 9.9 CRITICAL | Foreman: safemode bypass leading to rce |
| CVE-2026-96659 | 9.1 CRITICAL | Foreman: excessive permissions for viewer role on preview |
| CVE-2026-86345 | 9.0 CRITICAL | 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to f |
| CVE-2026-12405 | 8.8 HIGH | Rubygem-foreman_remote_execution: command injection in job invocations via effective_user |
| CVE-2026-12540 | 8.2 HIGH | Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter |
| CVE-2026-12541 | 8.2 HIGH | Foreman: command injection in foreman-rake database tasks |
| CVE-2026-12544 | 7.7 HIGH | Foreman: ssti and insecure deserialization in foreman-rake configuration |
| CVE-2026-86344 | 7.5 HIGH | 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-oper |
| CVE-2026-12423 | 7.5 HIGH | Foreman: unauthenticated information disclosure via provisioning token validation flaw |
| CVE-2026-96577 | 7.1 HIGH | Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without a |
| CVE-2026-56097 | 6.5 MEDIUM | Rubygem-katello: sql injection in registry proxy via labels |
| CVE-2026-103884 | 6.5 MEDIUM | Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allow |
| CVE-2026-83589 | 6.1 MEDIUM | Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect |
| CVE-2026-103754 | 5.9 MEDIUM | Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows |
| CVE-2026-103641 | 5.5 MEDIUM | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder |
| CVE-2026-12542 | 5.3 MEDIUM | Foreman: command injection in foreman-tail |
| CVE-2026-56098 | 4.3 MEDIUM | Rubygem-katello: improper authorization logic allows resource enumeration |
No comments yet