Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2015-3235 Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unsp… Foreman after 1.8.2 Fix from $1,6002015-08-14 MEDIUM 5.0 CVE-2015-3155 Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to captu… Foreman after 1.8.0 Fix from $1,6002015-08-14 MEDIUM 5.0 CVE-2015-1816 Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a craft… Foreman after 1.7.3 Fix from $1,6002015-08-14 MEDIUM 6.4 CVE-2014-4507 Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files … Foreman after 1.4.4 Fix from $1,6002014-06-20 HIGH 7.5 CVE-2014-0007EPSS 9% The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the … Foreman after 1.4.4 Fix from $1,9502014-06-20 MEDIUM 5.0 CVE-2014-0192 Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive inf… Foreman Patch available Fix from $1,6002014-05-08 MEDIUM 6.8 CVE-2014-0090 Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie. Foreman after 1.4.1 Fix from $1,6002014-05-08 HIGH 7.5 CVE-2013-0171 Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API. Foreman after 1.0 Fix from $1,9502014-05-08 HIGH 7.5 CVE-2013-0210 The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Pupp… Foreman after 1.0 Fix from $1,9502014-05-08 MEDIUM 6.5 CVE-2013-0187 Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request. Foreman after 1.0 Fix from $1,6002014-05-08 MEDIUM 5.0 CVE-2013-0173 Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attac… Foreman after 1.0 Fix from $1,6002014-05-08 MEDIUM 5.0 CVE-2013-0174 The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request. Foreman after 1.0 Fix from $1,6002014-05-08 HIGH 7.5 CVE-2012-5648 Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to… Foreman after 1.0 Fix from $1,9502014-04-04