Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2024-7700
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Ho…
Foreman
Mitigation only
HIGH 7.8
CVE-2021-20260
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host…
Foreman
Mitigation only
HIGH 7.1
CVE-2021-3456
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that shou…
Smart Proxy Salt
after 2.1.5
MEDIUM 6.1
CVE-2021-20290
An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that …
Openscap
0.9.1+
HIGH 7.8
CVE-2021-20259
A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with vi…
Foremanfogproxmox
0.13.1+
MEDIUM 5.4
CVE-2021-3469
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the …
Foreman
2.3.4+
MEDIUM 6.1
CVE-2021-3457
An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions tha…
Smart Proxy Shell Hooks
0.9.2+
MEDIUM 5.9
CVE-2021-3494
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. T…
Foreman
2.5.0+
MEDIUM 5.3
CVE-2014-0091
Foreman has improper input validation which could lead to partial Denial of Service
Foreman
No fix yet
HIGH 7.5
CVE-2013-4120
Katello has a Denial of Service vulnerability in API OAuth authentication
Katello
No fix yet
MEDIUM 5.4
CVE-2013-0283
Katello: Username in Notification page has cross site scripting
Katello
No fix yet
MEDIUM 5.4
CVE-2018-14664
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the brea…
Foreman
Mitigation only
CRITICAL 9.8
CVE-2018-14643EPSS 6%
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely exec…
Foreman
Patch available
MEDIUM 5.4
CVE-2016-8634
A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of …
Foreman
Mitigation only
MEDIUM 6.1
CVE-2016-8613
A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that …
Foreman
Patch available
MEDIUM 6.1
CVE-2017-7535
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to active…
Foreman
1.16.0+
MEDIUM 5.4
CVE-2014-3531
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML v…
Foreman
after 1.5.1
MEDIUM 5.4
CVE-2014-0208
Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inj…
Foreman
after 1.4.3
HIGH 8.1
CVE-2015-5246
The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving th…
Foreman
Patch available
MEDIUM 6.1
CVE-2015-5282
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
Foreman
Patch available
HIGH 8.1
CVE-2015-5152
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta…
Foreman
Mitigation only
HIGH 8.8
CVE-2017-7505
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to so…
Foreman
Patch available
MEDIUM 5.4
CVE-2016-6320
Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users…
Foreman
after 1.12.1
MEDIUM 6.1
CVE-2016-6319
Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugi…
Foreman
after 1.12.1
MEDIUM 5.3
CVE-2016-5390
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitiv…
Foreman
1.11.4 / 1.12.1+
MEDIUM 5.3
CVE-2016-4995
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated…
Foreman
1.11.4 / 1.12.1+
HIGH 8.8
CVE-2016-4475
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass …
Foreman
after 1.11.3
MEDIUM 5.0
CVE-2016-4451
The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited fil…
Foreman
after 1.11.2
HIGH 8.8
CVE-2016-3728
Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote att…
Foreman
Patch available
MEDIUM 5.4
CVE-2016-2100
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1…
Foreman
after 1.10.2