VYPR

Foreman

by Theforeman

gem: foreman

Source repositories

CVEs (87)

  • CVE-2025-9572MedFeb 27, 2026
    risk 0.33cvss 5.0epss 0.00

    n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.

  • CVE-2021-20290MedMar 25, 2022
    risk 0.33cvss 6.1epss 0.00

    An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources…

  • CVE-2016-8639MedAug 1, 2018
    risk 0.33cvss 6.1epss 0.01

    It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.

  • CVE-2015-5282MedSep 25, 2017
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.

  • CVE-2016-4451MedAug 19, 2016
    risk 0.33cvss 5.0epss 0.01

    The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging…

  • CVE-2026-13316MedJun 30, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

  • CVE-2020-10710MedAug 16, 2022
    risk 0.29cvss 4.4epss 0.00

    A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.

  • CVE-2014-3531MedOct 18, 2017
    risk 0.28cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.

  • CVE-2015-5233MedApr 11, 2016
    risk 0.27cvss 4.2epss 0.01

    Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to…

  • CVE-2016-9593MedApr 16, 2018
    risk 0.24cvss 4.7epss 0.01

    foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.

  • CVE-2026-5138MedJul 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested…

  • CVE-2025-2157LowMar 15, 2025
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege…

  • CVE-2016-7078MedSep 10, 2018
    risk 0.21cvss 4.3epss 0.01

    foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are…

  • CVE-2016-7077MedSep 10, 2018
    risk 0.21cvss 4.3epss 0.01

    foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.

  • CVE-2013-2121Jul 31, 2013
    risk 0.05cvss epss 0.25

    Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.

  • CVE-2013-2113Jul 31, 2013
    risk 0.05cvss epss 0.21

    The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.

  • CVE-2014-0007Jun 20, 2014
    risk 0.04cvss epss 0.09

    The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.

  • CVE-2026-5142MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data…

  • CVE-2026-5135MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes,…

  • CVE-2021-3584HigDec 23, 2021
    risk 0.00cvss 7.2epss 0.04

    A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity…