VYPR
Vendor

Theforeman

Products
21
CVEs
114
Across products
130
Status
Private

Products

21

Recent CVEs

114
View all 114 CVEs →
  • CVE-2024-7012CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP…

  • CVE-2023-0118CriSep 20, 2023
    risk 0.59cvss 9.1epss 0.01

    An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system.

  • CVE-2021-3590HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2017-7505HigMay 26, 2017
    risk 0.57cvss 8.8epss 0.02

    Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope,…

  • CVE-2016-4475HigAug 19, 2016
    risk 0.57cvss 8.8epss 0.03

    The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified…

  • CVE-2016-3728HigMay 20, 2016
    risk 0.57cvss 8.8epss 0.03

    Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/.

  • CVE-2012-3503CriAug 25, 2012
    risk 0.57cvss 9.8epss 0.03

    The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web…

  • CVE-2017-2667HigMar 12, 2018
    risk 0.53cvss 8.1epss 0.01

    Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

  • CVE-2015-5246HigOct 6, 2017
    risk 0.53cvss 8.1epss 0.01

    The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

  • CVE-2015-5152HigJul 17, 2017
    risk 0.53cvss 8.1epss 0.02

    Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

  • CVE-2023-0462HigSep 20, 2023
    risk 0.52cvss 8.0epss 0.01

    An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.

  • CVE-2026-12112HigJun 23, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without…

  • CVE-2021-20260HigAug 26, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2026-5136HigJul 1, 2026
    risk 0.50cvss 8.8epss 0.00

    A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a…

  • CVE-2016-3072HigJun 7, 2016
    risk 0.50cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.

  • CVE-2024-6861HigNov 6, 2024
    risk 0.49cvss 7.5epss 0.01

    A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

  • CVE-2013-4120HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.01

    Katello has a Denial of Service vulnerability in API OAuth authentication

  • CVE-2018-16861HigDec 7, 2018
    risk 0.49cvss 7.6epss 0.01

    A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code…

  • CVE-2014-8183HigAug 1, 2019
    risk 0.48cvss 7.4epss 0.01

    It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

  • CVE-2021-3456HigMar 30, 2022
    risk 0.46cvss 7.1epss 0.00

    An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and…