Vendor
Theforeman
Products
5
CVEs
51
Across products
332
Status
Private
Products
5- 264 CVEs
- 41 CVEs
- 17 CVEs
- 9 CVEs
- 1 CVE
Recent CVEs
51| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-7505 | Hig | 0.57 | 8.8 | 0.00 | May 26, 2017 | Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords. | |
| CVE-2016-3728 | Hig | 0.57 | 8.8 | 0.02 | May 20, 2016 | Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/. | |
| CVE-2012-3503 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2012 | The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token. | |
| CVE-2015-5246 | Hig | 0.53 | 8.1 | 0.01 | Oct 6, 2017 | The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory. | |
| CVE-2015-5152 | Hig | 0.53 | 8.1 | 0.00 | Jul 17, 2017 | Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack. | |
| CVE-2017-15100 | Med | 0.40 | 6.1 | 0.00 | Nov 27, 2017 | An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page. | |
| CVE-2015-5282 | Med | 0.40 | 6.1 | 0.00 | Sep 25, 2017 | Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after. | |
| CVE-2014-3531 | Med | 0.35 | 5.4 | 0.00 | Oct 18, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description. | |
| CVE-2014-0208 | Med | 0.35 | 5.4 | 0.00 | Oct 16, 2017 | Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted key name. | |
| CVE-2016-6320 | Med | 0.35 | 5.4 | 0.00 | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form. | |
| CVE-2016-2100 | Med | 0.35 | 5.4 | 0.00 | May 20, 2016 | Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission. | |
| CVE-2016-5390 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2016 | Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces. | |
| CVE-2016-4995 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2016 | Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname. | |
| CVE-2015-5233 | Med | 0.27 | 4.2 | 0.00 | Apr 11, 2016 | Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs. | |
| CVE-2013-2143 | 0.08 | — | 0.61 | Apr 17, 2014 | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account. | ||
| CVE-2013-2121 | 0.08 | — | 0.61 | Jul 31, 2013 | Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute. | ||
| CVE-2013-2113 | 0.07 | — | 0.47 | Jul 31, 2013 | The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role. | ||
| CVE-2014-0007 | 0.04 | — | 0.06 | Jun 20, 2014 | The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file. | ||
| CVE-2025-9572 | 0.00 | — | 0.00 | Feb 27, 2026 | n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass. | ||
| CVE-2014-0183 | 0.00 | — | 0.00 | Jan 2, 2020 | Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. |