CVE-2013-2121: Red Hat Openstack

Medium severity, CVSS 6.0. EPSS: 24.8% chance of exploitation in the next 30 days.

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.

Affected products

  • Red Hat Openstack: version 3.0 only
  • Theforeman Foreman: up to and including 1.2.0; version 1.1 only

Published 2013-07-31. Last modified 2026-06-16.