A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Ho…
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host…
Foreman has improper input validation which could lead to partial Denial of Service
Katello has a Denial of Service vulnerability in API OAuth authentication
Katello: Username in Notification page has cross site scripting
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the brea…
A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of …
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta…