Foreman
Sign in to watchby Theforeman
CVEs (40)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-7505 | Hig | 0.57 | 8.8 | 0.00 | May 26, 2017 | Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords. | |
| CVE-2016-3728 | Hig | 0.57 | 8.8 | 0.02 | May 20, 2016 | Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/. | |
| CVE-2015-5246 | Hig | 0.53 | 8.1 | 0.01 | Oct 6, 2017 | The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory. | |
| CVE-2015-5152 | Hig | 0.53 | 8.1 | 0.00 | Jul 17, 2017 | Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack. | |
| CVE-2017-15100 | Med | 0.40 | 6.1 | 0.00 | Nov 27, 2017 | An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page. | |
| CVE-2015-5282 | Med | 0.40 | 6.1 | 0.00 | Sep 25, 2017 | Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after. | |
| CVE-2014-3531 | Med | 0.35 | 5.4 | 0.00 | Oct 18, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description. | |
| CVE-2014-0208 | Med | 0.35 | 5.4 | 0.00 | Oct 16, 2017 | Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted key name. | |
| CVE-2016-6320 | Med | 0.35 | 5.4 | 0.00 | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form. | |
| CVE-2016-2100 | Med | 0.35 | 5.4 | 0.00 | May 20, 2016 | Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission. | |
| CVE-2016-5390 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2016 | Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces. | |
| CVE-2016-4995 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2016 | Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname. | |
| CVE-2015-5233 | Med | 0.27 | 4.2 | 0.00 | Apr 11, 2016 | Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs. | |
| CVE-2013-2121 | 0.08 | — | 0.61 | Jul 31, 2013 | Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute. | ||
| CVE-2013-2113 | 0.07 | — | 0.47 | Jul 31, 2013 | The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role. | ||
| CVE-2014-0007 | 0.04 | — | 0.06 | Jun 20, 2014 | The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file. | ||
| CVE-2025-9572 | 0.00 | — | 0.00 | Feb 27, 2026 | n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass. | ||
| CVE-2014-8183 | 0.00 | — | 0.00 | Aug 1, 2019 | It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations. | ||
| CVE-2015-7518 | 0.00 | — | 0.00 | Dec 17, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit forms. | ||
| CVE-2015-3235 | 0.00 | — | 0.01 | Aug 14, 2015 | Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors. |
Page 1 of 2