Theforeman

Foreman

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.01%
  • Veröffentlicht 08.05.2014 14:29:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.

  • EPSS 0.25%
  • Veröffentlicht 08.05.2014 14:29:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.

  • EPSS 0.39%
  • Veröffentlicht 08.05.2014 14:29:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.

  • EPSS 0.81%
  • Veröffentlicht 08.05.2014 14:29:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.

  • EPSS 0.61%
  • Veröffentlicht 04.04.2014 14:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 27.03.2014 16:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

  • EPSS 0.35%
  • Veröffentlicht 20.11.2013 14:12:21
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.

  • EPSS 0.71%
  • Veröffentlicht 16.09.2013 19:14:38
  • Zuletzt bearbeitet 11.04.2025 00:51:21

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

  • EPSS 0.54%
  • Veröffentlicht 16.09.2013 19:14:38
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.

  • EPSS 22.08%
  • Veröffentlicht 31.07.2013 13:20:25
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role...