Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Foreman MEDIUM 6.5
CVE-2024-7700

A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Ho…

Mitigation only
Fix from $1,600 2024-08-12
Foreman HIGH 7.8
CVE-2021-20260

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host…

Mitigation only
Fix from $1,950 2022-08-26
Foreman MEDIUM 5.3
CVE-2014-0091

Foreman has improper input validation which could lead to partial Denial of Service

No fix yet
Fix from $1,600 2019-12-11
Katello HIGH 7.5
CVE-2013-4120

Katello has a Denial of Service vulnerability in API OAuth authentication

No fix yet
Fix from $1,950 2019-12-10
Katello MEDIUM 5.4
CVE-2013-0283

Katello: Username in Notification page has cross site scripting

No fix yet
Fix from $1,600 2019-12-05
Foreman MEDIUM 5.4
CVE-2018-14664

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the brea…

Mitigation only
Fix from $1,600 2018-10-12
Foreman MEDIUM 5.4
CVE-2016-8634

A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of …

Mitigation only
Fix from $1,600 2018-08-01
Foreman HIGH 8.1
CVE-2015-5152

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta…

Mitigation only
Fix from $1,950 2017-07-17