← Back to browse · API

CVE-2018-14643

Severity
CRITICAL
CVSS
9.8
EPSS
0.06056
Risk score
41.32
CISA KEV
No
PoC
No
Published
2018-09-21
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2018-0606, GHSA-GX5G-XCXJ-CX2W
Products
[UNKNOWN]:smart_proxy_dynflow n/a
Sources
euvd EUVD-2018-0606

Description

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.

References