CVE-2012-5477
- EPSS 0.13%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
CVE-2013-0171
- EPSS 3.22%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
- EPSS 0.4%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
CVE-2013-0187
- EPSS 0.53%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
CVE-2013-0210
- EPSS 0.5%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
CVE-2012-5648
- EPSS 0.74%
- Veröffentlicht 04.04.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
CVE-2014-0089
- EPSS 0.39%
- Veröffentlicht 27.03.2014 16:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.
CVE-2013-4386
- EPSS 0.52%
- Veröffentlicht 20.11.2013 14:12:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
CVE-2013-4182
- EPSS 0.7%
- Veröffentlicht 16.09.2013 19:14:38
- Zuletzt bearbeitet 11.04.2025 00:51:21
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
- EPSS 0.94%
- Veröffentlicht 16.09.2013 19:14:38
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.