Foreman
by Theforeman
Source repositories
CVEs (75)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-5282 | Med | 0.33 | 6.1 | 0.01 | Sep 25, 2017 | Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after. | ||
| CVE-2016-4451 | Med | 0.33 | 5.0 | 0.01 | Aug 19, 2016 | The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging… | ||
| CVE-2026-13316 | mod | 0.29 | 4.4 | — | Jun 18, 2026 | Foreman: SSRF to cloud metada service through unvalidated test_url parameters in Foreman config | ||
| CVE-2014-3531 | Med | 0.28 | 5.4 | 0.01 | Oct 18, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description. | ||
| CVE-2015-5233 | Med | 0.27 | 4.2 | 0.01 | Apr 11, 2016 | Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to… | ||
| CVE-2025-2157 | Low | 0.21 | 3.3 | 0.00 | Mar 15, 2025 | A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege… | ||
| CVE-2016-7078 | Med | 0.21 | 4.3 | 0.01 | Sep 10, 2018 | foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are… | ||
| CVE-2016-7077 | Med | 0.21 | 4.3 | 0.01 | Sep 10, 2018 | foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6. | ||
| CVE-2013-2121 | 0.05 | — | 0.25 | Jul 31, 2013 | Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute. | |||
| CVE-2013-2113 | 0.05 | — | 0.21 | Jul 31, 2013 | The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role. | |||
| CVE-2014-0007 | 0.04 | — | 0.09 | Jun 20, 2014 | The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file. | |||
| CVE-2025-9572 | 0.00 | — | 0.00 | Feb 27, 2026 | n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass. | |||
| CVE-2024-7012 | 0.00 | — | 0.01 | Sep 4, 2024 | An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP… | |||
| CVE-2024-7700 | 0.00 | — | 0.01 | Aug 12, 2024 | A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the necessary privileges to inject arbitrary commands into the configuration,… | |||
| CVE-2022-3874 | 0.00 | — | 0.02 | Sep 22, 2023 | A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the… | |||
| CVE-2023-0462 | 0.00 | — | 0.01 | Sep 20, 2023 | An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload. | |||
| CVE-2023-0118 | 0.00 | — | 0.01 | Sep 20, 2023 | An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system. | |||
| CVE-2023-0119 | 0.00 | — | 0.01 | Sep 12, 2023 | A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on… | |||
| CVE-2021-20260 | 0.00 | — | 0.00 | Aug 26, 2022 | A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |||
| CVE-2021-3590 | 0.00 | — | 0.01 | Aug 22, 2022 | A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
- risk 0.33cvss 5.0epss 0.01
The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging…
- risk 0.29cvss 4.4epss —
Foreman: SSRF to cloud metada service through unvalidated test_url parameters in Foreman config
- risk 0.28cvss 5.4epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.
- risk 0.27cvss 4.2epss 0.01
Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to…
- risk 0.21cvss 3.3epss 0.00
A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege…
- risk 0.21cvss 4.3epss 0.01
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are…
- risk 0.21cvss 4.3epss 0.01
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
- CVE-2013-2121Jul 31, 2013risk 0.05cvss —epss 0.25
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
- CVE-2013-2113Jul 31, 2013risk 0.05cvss —epss 0.21
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
- CVE-2014-0007Jun 20, 2014risk 0.04cvss —epss 0.09
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
- CVE-2025-9572Feb 27, 2026risk 0.00cvss —epss 0.00
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
- CVE-2024-7012Sep 4, 2024risk 0.00cvss —epss 0.01
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP…
- CVE-2024-7700Aug 12, 2024risk 0.00cvss —epss 0.01
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the necessary privileges to inject arbitrary commands into the configuration,…
- CVE-2022-3874Sep 22, 2023risk 0.00cvss —epss 0.02
A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the…
- CVE-2023-0462Sep 20, 2023risk 0.00cvss —epss 0.01
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
- CVE-2023-0118Sep 20, 2023risk 0.00cvss —epss 0.01
An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system.
- CVE-2023-0119Sep 12, 2023risk 0.00cvss —epss 0.01
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on…
- CVE-2021-20260Aug 26, 2022risk 0.00cvss —epss 0.00
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- CVE-2021-3590Aug 22, 2022risk 0.00cvss —epss 0.01
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Page 2 of 4