Forem
Products
1- 15 CVEs
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14643 | 0.01 | — | 0.09 | Sep 21, 2018 | An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context. | |||
| CVE-2023-27160 | 0.00 | — | 0.01 | Mar 31, 2023 | forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request. | |||
| CVE-2021-3584 | 0.00 | — | 0.00 | Dec 23, 2021 | A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity… | |||
| CVE-2021-3469 | 0.00 | — | 0.00 | Jun 3, 2021 | Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate requests that have subject alternative… | |||
| CVE-2021-3457 | 0.00 | — | 0.00 | May 12, 2021 | An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources… | |||
| CVE-2021-3494 | 0.00 | — | 0.00 | Apr 26, 2021 | A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions… | |||
| CVE-2014-0091 | 0.00 | — | 0.01 | Dec 11, 2019 | Foreman has improper input validation which could lead to partial Denial of Service | |||
| CVE-2019-3893 | 0.00 | — | 0.00 | Apr 9, 2019 | In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this… | |||
| CVE-2018-14664 | 0.00 | — | 0.00 | Oct 12, 2018 | A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be… | |||
| CVE-2016-7077 | 0.00 | — | 0.00 | Sep 10, 2018 | foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6. | |||
| CVE-2016-7078 | 0.00 | — | 0.00 | Sep 10, 2018 | foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are… | |||
| CVE-2016-8634 | 0.00 | — | 0.00 | Aug 1, 2018 | A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS… | |||
| CVE-2017-7535 | 0.00 | — | 0.01 | Jul 26, 2018 | foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action. | |||
| CVE-2017-2672 | 0.00 | — | 0.00 | Jun 21, 2018 | A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems. | |||
| CVE-2018-1096 | 0.00 | — | 0.00 | Apr 5, 2018 | An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database. |
- CVE-2018-14643Sep 21, 2018risk 0.01cvss —epss 0.09
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.
- CVE-2023-27160Mar 31, 2023risk 0.00cvss —epss 0.01
forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
- CVE-2021-3584Dec 23, 2021risk 0.00cvss —epss 0.00
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity…
- CVE-2021-3469Jun 3, 2021risk 0.00cvss —epss 0.00
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate requests that have subject alternative…
- CVE-2021-3457May 12, 2021risk 0.00cvss —epss 0.00
An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources…
- CVE-2021-3494Apr 26, 2021risk 0.00cvss —epss 0.00
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions…
- CVE-2014-0091Dec 11, 2019risk 0.00cvss —epss 0.01
Foreman has improper input validation which could lead to partial Denial of Service
- CVE-2019-3893Apr 9, 2019risk 0.00cvss —epss 0.00
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this…
- CVE-2018-14664Oct 12, 2018risk 0.00cvss —epss 0.00
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be…
- CVE-2016-7077Sep 10, 2018risk 0.00cvss —epss 0.00
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
- CVE-2016-7078Sep 10, 2018risk 0.00cvss —epss 0.00
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are…
- CVE-2016-8634Aug 1, 2018risk 0.00cvss —epss 0.00
A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS…
- CVE-2017-7535Jul 26, 2018risk 0.00cvss —epss 0.01
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.
- CVE-2017-2672Jun 21, 2018risk 0.00cvss —epss 0.00
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
- CVE-2018-1096Apr 5, 2018risk 0.00cvss —epss 0.00
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.