CyberRota Analysis
AI-GeneratedA command injection vulnerability exists in the Foreman application, specifically within the foreman-rake db:dump and db:import_dump tasks, due to inadequate sanitization of user inputs in the destination and file parameters. This flaw allows an attacker with appropriate permissions to execute arbitrary shell commands, potentially compromising the system. Organizations using Foreman should prioritize patching this vulnerability to mitigate the risk of unauthorized command execution.
Original NVD Description
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.