VYPR

foreman

by Red Hat

CVEs (5)

  • CVE-2025-10622HigNov 5, 2025
    risk 0.52cvss 8.0epss 0.01

    A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.

  • CVE-2023-0462HigSep 20, 2023
    risk 0.52cvss 8.0epss 0.01

    An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.

  • CVE-2023-4886MedOct 3, 2023
    risk 0.44cvss 6.7epss 0.00

    A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

  • CVE-2026-13316MedJun 30, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

  • CVE-2026-5142MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data…