Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-7700 A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Ho… Foreman Mitigation only Fix from $1,6002024-08-12 HIGH 7.8 CVE-2021-20260 A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host… Foreman Mitigation only Fix from $1,9502022-08-26 HIGH 7.1 CVE-2021-3456 An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that shou… Smart Proxy Salt after 2.1.5 Fix from $1,9502022-03-30 MEDIUM 6.1 CVE-2021-20290 An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that … Openscap 0.9.1+ Fix from $1,6002022-03-25 HIGH 7.8 CVE-2021-20259 A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with vi… Foremanfogproxmox 0.13.1+ Fix from $1,9502021-06-07 MEDIUM 5.4 CVE-2021-3469 Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the … Foreman 2.3.4+ Fix from $1,6002021-06-03 MEDIUM 6.1 CVE-2021-3457 An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions tha… Smart Proxy Shell Hooks 0.9.2+ Fix from $1,6002021-05-12 MEDIUM 5.9 CVE-2021-3494 A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. T… Foreman 2.5.0+ Fix from $1,6002021-04-26 MEDIUM 5.3 CVE-2014-0091 Foreman has improper input validation which could lead to partial Denial of Service Foreman No fix yet Fix from $1,6002019-12-11 HIGH 7.5 CVE-2013-4120 Katello has a Denial of Service vulnerability in API OAuth authentication Katello No fix yet Fix from $1,9502019-12-10 MEDIUM 5.4 CVE-2013-0283 Katello: Username in Notification page has cross site scripting Katello No fix yet Fix from $1,6002019-12-05 MEDIUM 5.4 CVE-2018-14664 A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the brea… Foreman Mitigation only Fix from $1,6002018-10-12 CRITICAL 9.8 CVE-2018-14643EPSS 6% An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely exec… Foreman Patch available Fix from $2,3002018-09-21 MEDIUM 5.4 CVE-2016-8634 A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of … Foreman Mitigation only Fix from $1,6002018-08-01 MEDIUM 6.1 CVE-2016-8613 A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that … Foreman Patch available Fix from $1,6002018-07-31 MEDIUM 6.1 CVE-2017-7535 foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to active… Foreman 1.16.0+ Fix from $1,6002018-07-26 MEDIUM 5.4 CVE-2014-3531 Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML v… Foreman after 1.5.1 Fix from $1,6002017-10-18 MEDIUM 5.4 CVE-2014-0208 Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inj… Foreman after 1.4.3 Fix from $1,6002017-10-16 HIGH 8.1 CVE-2015-5246 The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving th… Foreman Patch available Fix from $1,9502017-10-06 MEDIUM 6.1 CVE-2015-5282 Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after. Foreman Patch available Fix from $1,6002017-09-25 HIGH 8.1 CVE-2015-5152 Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta… Foreman Mitigation only Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-7505 Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to so… Foreman Patch available Fix from $1,9502017-05-26 MEDIUM 5.4 CVE-2016-6320 Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users… Foreman after 1.12.1 Fix from $1,6002016-08-19 MEDIUM 6.1 CVE-2016-6319 Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugi… Foreman after 1.12.1 Fix from $1,6002016-08-19 MEDIUM 5.3 CVE-2016-5390 Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitiv… Foreman 1.11.4 / 1.12.1+ Fix from $1,6002016-08-19 MEDIUM 5.3 CVE-2016-4995 Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated… Foreman 1.11.4 / 1.12.1+ Fix from $1,6002016-08-19 HIGH 8.8 CVE-2016-4475 The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass … Foreman after 1.11.3 Fix from $1,9502016-08-19 MEDIUM 5.0 CVE-2016-4451 The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited fil… Foreman after 1.11.2 Fix from $1,6002016-08-19 HIGH 8.8 CVE-2016-3728 Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote att… Foreman Patch available Fix from $1,9502016-05-20 MEDIUM 5.4 CVE-2016-2100 Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1… Foreman after 1.10.2 Fix from $1,6002016-05-20