{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "OS command injection vulnerability",
    "tracking": {
      "current_release_date": "2026-07-23T20:09:42+00:00",
      "generator": {
        "date": "2026-07-23T20:09:42+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2014-0156",
      "initial_release_date": "2014-03-27T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-23T20:09:42+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat CloudForms unspecified",
            "product": {
              "name": "Red Hat CloudForms unspecified",
              "product_id": "cfme-5",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:cloudforms_managementengine:5"
              }
            }
          },
          {
            "category": "product_version",
            "name": "cfme-gemset",
            "product": {
              "name": "cfme-gemset",
              "product_id": "cfme-gemset",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/cfme-gemset"
              }
            }
          },
          {
            "category": "product_version",
            "name": "cfme-gemset",
            "product": {
              "name": "cfme-gemset",
              "product_id": "cfme-gemset.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/cfme-gemset?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cfme-gemset as a component of Red Hat CloudForms unspecified",
          "product_id": "cfme-5:cfme-gemset"
        },
        "product_reference": "cfme-gemset",
        "relates_to_product_reference": "cfme-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cfme-gemset.src as a component of Red Hat CloudForms unspecified",
          "product_id": "cfme-5:cfme-gemset.src"
        },
        "product_reference": "cfme-gemset.src",
        "relates_to_product_reference": "cfme-5"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-0156",
      "cwe": {
        "id": "CWE-78",
        "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
      },
      "discovery_date": "2014-03-27T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "cfme-5:cfme-gemset",
            "cfme-5:cfme-gemset.src"
          ]
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "cfme-5:cfme-gemset",
          "cfme-5:cfme-gemset.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-0156"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0156"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-0156"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 8.1,
            "baseSeverity": "HIGH"
          },
          "products": [
            "cfme-5:cfme-gemset",
            "cfme-5:cfme-gemset.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "cfme-5:cfme-gemset",
            "cfme-5:cfme-gemset.src"
          ]
        }
      ],
      "title": "OS command injection vulnerability"
    }
  ]
}