HIGH8.3
GHSA-hfcp-477w-3wjw
rubyipmi is vulnerable to OS Command Injection through malicious usernames
Quick fix
GHSA-hfcp-477w-3wjw — rubyipmi: upgrade to the fixed version with the command below.
bundle update rubyipmiDetails
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-0980[ADVISORY]
- https://github.com/logicminds/rubyipmi/commit/252503a7b4dca68388165883b0322024e344a215[WEB]
- https://access.redhat.com/errata/RHSA-2026:5968[WEB]
- https://access.redhat.com/errata/RHSA-2026:5970[WEB]
- https://access.redhat.com/errata/RHSA-2026:5971[WEB]
- https://access.redhat.com/security/cve/CVE-2026-0980[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2429874[WEB]
- https://github.com/logicminds/rubyipmi[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubyipmi/CVE-2026-0980.yml[WEB]