CVE-2023-0462
NixOS vulnerability analysis and mitigation

Overview

An arbitrary code execution vulnerability (CVE-2023-0462) was discovered in Foreman, affecting Red Hat Satellite and Foreman systems. The vulnerability was disclosed and addressed through multiple security advisories in October 2023. This flaw allows an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload (Red Hat Advisory, Bugzilla).

Technical details

The vulnerability exists in the global parameters functionality of Foreman. Specifically, when creating a YAML global parameter under 'Configure->Global Parameters', an attacker with admin privileges can craft a malicious payload that leads to arbitrary code execution on the underlying operating system. The issue was fixed in Foreman version 3.8.0 by implementing YAML.safeload instead of YAML.load ([Bugzilla](https://bugzilla.redhat.com/showbug.cgi?id=2162970)).

Impact

The vulnerability allows authenticated administrators to execute arbitrary code on the underlying operating system through specially crafted YAML payloads in global parameters. This could potentially lead to complete system compromise within the scope of the application's permissions (Red Hat Advisory).

Mitigation and workarounds

Red Hat has released security updates to address this vulnerability across multiple versions of Satellite. Users are advised to upgrade to the patched versions available through RHSA-2023:5980 for Satellite 6.11, RHSA-2023:5979 for Satellite 6.12, and RHSA-2023:5931 for Satellite 6.13 (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox_esr
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management