{"id":"CVE-2025-10622","summary":"Foreman: os command injection via ct_location and fcct_location parameters","details":"A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.","modified":"2026-05-18T05:58:02.504925353Z","published":"2025-11-05T07:32:14.390Z","database_specific":{"cwe_ids":["CWE-78"],"cna_assigner":"redhat","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10622.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://theforeman.org/security.html#2025-10622"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:19721"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:19832"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:19855"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:19856"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-10622"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10622.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10622"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2396020"},{"type":"PACKAGE","url":"https://github.com/theforeman/foreman"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/theforeman/foreman","events":[{"introduced":"d88839af35cb6ea7b8ca4ba98447646b2b111839"},{"fixed":"0a500b4e8310cc0911da9761654efc67441cf56e"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"3.12.0"},{"fixed":"3.16.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-10622.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}