Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Foreman MEDIUM 6.5
CVE-2024-7700

A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Ho…

Mitigation only
Fix from $1,600 2024-08-12
Foreman HIGH 7.8
CVE-2021-20260

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host…

Mitigation only
Fix from $1,950 2022-08-26
Smart Proxy Salt HIGH 7.1
CVE-2021-3456

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that shou…

Fix: after 2.1.5
Fix from $1,950 2022-03-30
Openscap MEDIUM 6.1
CVE-2021-20290

An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that …

Fix: 0.9.1+
Fix from $1,600 2022-03-25
Foremanfogproxmox HIGH 7.8
CVE-2021-20259

A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with vi…

Fix: 0.13.1+
Fix from $1,950 2021-06-07
Foreman MEDIUM 5.4
CVE-2021-3469

Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the …

Fix: 2.3.4+
Fix from $1,600 2021-06-03
Smart Proxy Shell Hooks MEDIUM 6.1
CVE-2021-3457

An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions tha…

Fix: 0.9.2+
Fix from $1,600 2021-05-12
Foreman MEDIUM 5.9
CVE-2021-3494

A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. T…

Fix: 2.5.0+
Fix from $1,600 2021-04-26
Foreman MEDIUM 5.3
CVE-2014-0091

Foreman has improper input validation which could lead to partial Denial of Service

No fix yet
Fix from $1,600 2019-12-11
Katello HIGH 7.5
CVE-2013-4120

Katello has a Denial of Service vulnerability in API OAuth authentication

No fix yet
Fix from $1,950 2019-12-10
Katello MEDIUM 5.4
CVE-2013-0283

Katello: Username in Notification page has cross site scripting

No fix yet
Fix from $1,600 2019-12-05
Foreman MEDIUM 5.4
CVE-2018-14664

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the brea…

Mitigation only
Fix from $1,600 2018-10-12
Foreman CRITICAL 9.8
CVE-2018-14643EPSS 6%

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely exec…

Patch available
Fix from $2,300 2018-09-21
Foreman MEDIUM 5.4
CVE-2016-8634

A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of …

Mitigation only
Fix from $1,600 2018-08-01
Foreman MEDIUM 6.1
CVE-2016-8613

A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that …

Patch available
Fix from $1,600 2018-07-31
Foreman MEDIUM 6.1
CVE-2017-7535

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to active…

Fix: 1.16.0+
Fix from $1,600 2018-07-26
Foreman MEDIUM 5.4
CVE-2014-3531

Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML v…

Fix: after 1.5.1
Fix from $1,600 2017-10-18
Foreman MEDIUM 5.4
CVE-2014-0208

Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inj…

Fix: after 1.4.3
Fix from $1,600 2017-10-16
Foreman HIGH 8.1
CVE-2015-5246

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving th…

Patch available
Fix from $1,950 2017-10-06
Foreman MEDIUM 6.1
CVE-2015-5282

Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.

Patch available
Fix from $1,600 2017-09-25
Foreman HIGH 8.1
CVE-2015-5152

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta…

Mitigation only
Fix from $1,950 2017-07-17
Foreman HIGH 8.8
CVE-2017-7505

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to so…

Patch available
Fix from $1,950 2017-05-26
Foreman MEDIUM 5.4
CVE-2016-6320

Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users…

Fix: after 1.12.1
Fix from $1,600 2016-08-19
Foreman MEDIUM 6.1
CVE-2016-6319

Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugi…

Fix: after 1.12.1
Fix from $1,600 2016-08-19
Foreman MEDIUM 5.3
CVE-2016-5390

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitiv…

Fix: 1.11.4 / 1.12.1+
Fix from $1,600 2016-08-19
Foreman MEDIUM 5.3
CVE-2016-4995

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated…

Fix: 1.11.4 / 1.12.1+
Fix from $1,600 2016-08-19
Foreman HIGH 8.8
CVE-2016-4475

The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass …

Fix: after 1.11.3
Fix from $1,950 2016-08-19
Foreman MEDIUM 5.0
CVE-2016-4451

The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited fil…

Fix: after 1.11.2
Fix from $1,600 2016-08-19
Foreman HIGH 8.8
CVE-2016-3728

Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote att…

Patch available
Fix from $1,950 2016-05-20
Foreman MEDIUM 5.4
CVE-2016-2100

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1…

Fix: after 1.10.2
Fix from $1,600 2016-05-20