- EPSS 0.73%
- Published 23.12.2021 20:15:11
- Last modified 21.11.2024 06:21:54
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is t...
CVE-2021-3469
- EPSS 0.1%
- Published 03.06.2021 20:15:08
- Last modified 21.11.2024 06:21:37
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate requests th...
CVE-2021-3494
- EPSS 0.25%
- Published 26.04.2021 15:15:07
- Last modified 21.11.2024 06:21:40
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated...
CVE-2014-0091
- EPSS 0.51%
- Published 11.12.2019 15:15:14
- Last modified 21.11.2024 02:01:20
Foreman has improper input validation which could lead to partial Denial of Service
CVE-2014-8183
- EPSS 0.15%
- Published 01.08.2019 14:15:10
- Last modified 21.11.2024 02:18:43
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
CVE-2019-3893
- EPSS 1.28%
- Published 09.04.2019 16:29:02
- Last modified 21.11.2024 04:42:48
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resou...
CVE-2018-16861
- EPSS 0.39%
- Published 07.12.2018 19:29:00
- Last modified 21.11.2024 03:53:28
A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possib...
CVE-2018-14664
- EPSS 0.33%
- Published 12.10.2018 22:15:07
- Last modified 21.11.2024 03:49:32
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs b...
- EPSS 8.95%
- Published 21.09.2018 13:29:00
- Last modified 21.11.2024 03:49:29
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged co...
CVE-2016-7078
- EPSS 0.24%
- Published 10.09.2018 15:29:04
- Last modified 21.11.2024 02:57:24
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's vi...