VYPR

Foreman

by Theforeman

gem: foreman

Source repositories

CVEs (87)

  • CVE-2013-0171May 8, 2014
    risk 0.00cvss epss 0.03

    Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.

  • CVE-2012-5477May 8, 2014
    risk 0.00cvss epss 0.00

    The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.

  • CVE-2012-5648Apr 4, 2014
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.

  • CVE-2014-0089Mar 27, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

  • CVE-2013-4386Nov 20, 2013
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.

  • CVE-2013-4182Sep 16, 2013
    risk 0.00cvss epss 0.02

    app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

  • CVE-2013-4180Sep 16, 2013
    risk 0.00cvss epss 0.02

    The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.

Page 5 of 5