Unrated severityNVD Advisory· Published Jul 31, 2013· Updated Apr 29, 2026
CVE-2013-2121
CVE-2013-2121
Description
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
Affected products
3cpe:2.3:a:theforeman:foreman:1.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:theforeman:foreman:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:theforeman:foreman:*:rc1:*:*:*:*:*:*range: <=1.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.