Foreman Project Foreman vulnerabilities
3 known vulnerabilities affecting foreman_project/foreman.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-1096MEDIUMCVSS 6.5vbefore 1.16.12018-04-05
CVE-2018-1096 [MEDIUM] CWE-89 CVE-2018-1096: An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
cvelistv5nvd
CVE-2018-1097HIGHCVSS 8.8vbefore 1.16.12018-04-04
CVE-2018-1097 [HIGH] CWE-200 CVE-2018-1097: A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for power
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
cvelistv5nvd
CVE-2017-15100MEDIUMCVSS 6.1v1.2 and later, a fix is planned for 1.16.02017-11-27
CVE-2017-15100 [MEDIUM] CWE-79 CVE-2017-15100: An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.
cvelistv5nvd