VYPR

Foreman

by Theforeman

gem: foreman

Source repositories

CVEs (87)

  • CVE-2021-20259HigJun 7, 2021
    risk 0.00cvss 7.8epss 0.00

    A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…

  • CVE-2019-3893MedApr 9, 2019
    risk 0.00cvss 4.9epss 0.02

    In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this…

  • CVE-2018-14643CriSep 21, 2018
    risk 0.00cvss 9.8epss 0.06

    An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.

  • CVE-2018-1097HigApr 4, 2018
    risk 0.00cvss 8.8epss 0.02

    A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.

  • CVE-2015-7518Dec 17, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit…

  • CVE-2015-3235Aug 14, 2015
    risk 0.00cvss epss 0.02

    Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

  • CVE-2015-3155Aug 14, 2015
    risk 0.00cvss epss 0.02

    Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

  • CVE-2015-1844Aug 14, 2015
    risk 0.00cvss epss 0.02

    Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.

  • CVE-2015-1816Aug 14, 2015
    risk 0.00cvss epss 0.01

    Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.

  • CVE-2014-3653Jul 6, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

  • CVE-2014-3691Mar 9, 2015
    risk 0.00cvss epss 0.02

    Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.

  • CVE-2014-3492Jul 1, 2014
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host.

  • CVE-2014-3491Jul 1, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes.

  • CVE-2014-4507Jun 20, 2014
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.

  • CVE-2014-0192May 8, 2014
    risk 0.00cvss epss 0.02

    Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."

  • CVE-2014-0090May 8, 2014
    risk 0.00cvss epss 0.01

    Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.

  • CVE-2013-0210May 8, 2014
    risk 0.00cvss epss 0.02

    The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.

  • CVE-2013-0187May 8, 2014
    risk 0.00cvss epss 0.01

    Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.

  • CVE-2013-0174May 8, 2014
    risk 0.00cvss epss 0.02

    The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.

  • CVE-2013-0173May 8, 2014
    risk 0.00cvss epss 0.01

    Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attack.

Page 4 of 5