The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-07-03T16:00:00

Updated: 2024-08-06T20:05:12.537Z

Reserved: 2012-06-14T00:00:00

Link: CVE-2012-3366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-07-03T16:40:35.007

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-3366

cve-icon Redhat

No data.