CVE-2014-3653
- EPSS 0.28%
- Veröffentlicht 06.07.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.
CVE-2014-3691
- EPSS 0.35%
- Veröffentlicht 09.03.2015 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request withou...
CVE-2014-3492
- EPSS 0.23%
- Veröffentlicht 01.07.2014 16:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host.
CVE-2014-3491
- EPSS 0.23%
- Veröffentlicht 01.07.2014 16:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification...
CVE-2014-4507
- EPSS 0.84%
- Veröffentlicht 20.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
CVE-2014-0007
- EPSS 5.97%
- Veröffentlicht 20.06.2014 14:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
- EPSS 0.31%
- Veröffentlicht 08.05.2014 14:29:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
CVE-2014-0090
- EPSS 0.41%
- Veröffentlicht 08.05.2014 14:29:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
- EPSS 0.26%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attack.
CVE-2012-5477
- EPSS 0.05%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.