CVE-2023-0462
- EPSS 0.96%
- Veröffentlicht 20.09.2023 14:15:12
- Zuletzt bearbeitet 21.11.2024 07:37:13
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
CVE-2021-20260
- EPSS 0.2%
- Veröffentlicht 26.08.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:13
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as ...
CVE-2021-3590
- EPSS 0.65%
- Veröffentlicht 22.08.2022 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:55
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as syst...
CVE-2020-10710
- EPSS 0.23%
- Veröffentlicht 16.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 04:55:54
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext p...
- EPSS 3.89%
- Veröffentlicht 23.12.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:21:54
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is t...
CVE-2021-3469
- EPSS 0.33%
- Veröffentlicht 03.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:37
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate requests th...
CVE-2021-3494
- EPSS 0.37%
- Veröffentlicht 26.04.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:40
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated...
CVE-2014-0091
- EPSS 1.55%
- Veröffentlicht 11.12.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 02:01:20
Foreman has improper input validation which could lead to partial Denial of Service
CVE-2014-8183
- EPSS 0.75%
- Veröffentlicht 01.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 02:18:43
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
CVE-2019-3893
- EPSS 1.83%
- Veröffentlicht 09.04.2019 16:29:02
- Zuletzt bearbeitet 21.11.2024 04:42:48
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resou...