Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
foreman vulnerabilities and exploits
(subscribe to this query)
5.9
CVSSv3
CVE-2021-3494
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions ...
9.8
CVSSv3
CVE-2017-7540
rubygem-safemode, as used in Foreman, versions 1.3.2 and previous versions are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.
Safemode Project Safemode
7.2
CVSSv3
CVE-2018-14666
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
Redhat Satellite
NA
CVE-2014-0135
Kafo prior to 0.3.17 and 0.4.x prior to 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.
Theforeman Kafo 0.5.1
Theforeman Kafo 0.3.11
Theforeman Kafo 0.3.9
Theforeman Kafo 0.3.4
Theforeman Kafo 0.3.2
Theforeman Kafo 0.0.17
Theforeman Kafo 0.0.15
Theforeman Kafo 0.0.8
Theforeman Kafo 0.0.6
Theforeman Kafo 0.0.1
Theforeman Kafo
Theforeman Kafo 0.3.15
Theforeman Kafo 0.3.14
Theforeman Kafo 0.3.13
Theforeman Kafo 0.3.0
Theforeman Kafo 0.2.2
Theforeman Kafo 0.2.1
Theforeman Kafo 0.2.0
Theforeman Kafo 0.1.0
Theforeman Kafo 0.0.5
Theforeman Kafo 0.0.4
Theforeman Kafo 0.0.3
6.5
CVSSv3
CVE-2014-3590
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.
Redhat Satellite 6.0
8.1
CVSSv3
CVE-2017-2667
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Theforeman Hammer Cli
Redhat Satellite 6.3
Redhat Satellite Capsule 6.3
7.8
CVSSv3
CVE-2021-20259
A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availabi...
Theforeman Foremanfogproxmox
5.4
CVSSv3
CVE-2023-0119
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on...
Redhat Satellite 6.13
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-2907
hardcoded
inject
CVE-2024-20359
CVE-2024-2467
CVE-2024-4077
CVE-2024-22391
camera
CVE-2024-20353
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6