ManageIQ is an open-source infrastructure and cloud management platform whose vulnerability exposure centers on code-injection and command-injection weaknesses in its core components, particularly the AwesomeSpawn subprocess-handling library and ManageIQ itself. These injection-oriented flaws reflect the interaction-heavy nature of a multi-tenant orchestration tool that must parse and execute commands across heterogeneous infrastructure endpoints. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Manageiq over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0156CRITICAL Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in co | Jun 30, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-32756HIGH ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privileg | Jul 21, 2021 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Manageiq.
Media articles that mention a CVE ID that affects a product developed by Manageiq — matched by CVE ID, not by vendor name.