The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
| Software | From | Fixed in |
|---|---|---|
| theforeman / foreman | 0.2 | 0.2.x |
| theforeman / foreman | 0.4.1 | 0.4.1.x |
| theforeman / foreman | 0.3 | 0.3.x |
| theforeman / foreman | - | 1.0.x |
| theforeman / foreman | 0.1 | 0.1.x |
| theforeman / foreman | 0.4 | 0.4.x |