VDB
Sign up
HIGH8.3

GHSA-hfcp-477w-3wjw

rubyipmi is vulnerable to OS Command Injection through malicious usernames

Quick fix

GHSA-hfcp-477w-3wjw — rubyipmi: upgrade to the fixed version with the command below.

bundle update rubyipmi

Details

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rubyipmi
Introduced in: 0Fixed in: 0.13.0
Fixbundle update rubyipmi

References