- EPSS 1.54%
- Veröffentlicht 08.05.2014 14:29:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
CVE-2014-0090
- EPSS 1.38%
- Veröffentlicht 08.05.2014 14:29:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
CVE-2013-0187
- EPSS 1.08%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
CVE-2012-5477
- EPSS 0.33%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
CVE-2013-0171
- EPSS 2.97%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
- EPSS 1.12%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attack.
- EPSS 1.67%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
CVE-2013-0210
- EPSS 1.85%
- Veröffentlicht 08.05.2014 14:29:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
CVE-2012-5648
- EPSS 2.14%
- Veröffentlicht 04.04.2014 14:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
CVE-2014-0089
- EPSS 1.89%
- Veröffentlicht 27.03.2014 16:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.