Theforeman Foreman vulnerabilities

64 known vulnerabilities affecting theforeman/foreman.

Total CVEs
64
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM44LOW1

Vulnerabilities

Page 1 of 4
CVE-2025-9572MEDIUMCVSS 6.5≥ 1.22.0, < 3.16.22026-02-27
CVE-2025-9572 [MEDIUM] CWE-863 CVE-2025-9572: n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
nvd
CVE-2023-4886MEDIUMCVSS 4.4fixed in 3.8.02023-10-03
CVE-2023-4886 [MEDIUM] CWE-200 CVE-2023-4886: A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
nvd
CVE-2023-0462CRITICALCVSS 9.1fixed in 3.8.02023-09-20
CVE-2023-0462 [HIGH] CWE-94 CVE-2023-0462: An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
nvd
CVE-2021-3590HIGHCVSS 8.8≥ 1.6.02022-08-22
CVE-2021-3590 [HIGH] CWE-200 CVE-2021-3590: A flaw was found in Foreman project. A credential leak was identified which will expose Azure Comput A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-10710MEDIUMCVSS 4.4fixed in 1.24.1.222022-08-16
CVE-2020-10710 [MEDIUM] CWE-522 CVE-2020-10710: A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellit A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.
nvd
CVE-2021-3584HIGHCVSS 7.2fixed in 2.4.1≥ 2.5.0, < 2.5.1+1 more2021-12-23
CVE-2021-3584 [HIGH] CWE-78 CVE-2021-3584: A server side remote code execution vulnerability was found in Foreman project. A authenticated atta A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.
nvd
CVE-2021-3469MEDIUMCVSS 5.4fixed in 2.3.42021-06-03
CVE-2021-3469 [MEDIUM] CWE-863 CVE-2021-3469: Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling fla Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate requests that have subject alternative names (SANs). Foreman do not enable SANs by default and `allow-authorizatio
nvd
CVE-2021-3494MEDIUMCVSS 5.9fixed in 2.5.02021-04-26
CVE-2021-3494 [MEDIUM] CWE-319 CVE-2021-3494: A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the f A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions in FreeIPA if certain conditions are met. The highest threat from this fl
nvd
CVE-2014-8183HIGHCVSS 7.4≥ 1.0, < 1.15.6v1.x.x before 1.15.62019-08-01
CVE-2014-8183 [HIGH] CWE-284 CVE-2014-8183: It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce acc It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
cvelistv5nvd
CVE-2019-3893MEDIUMCVSS 4.9≥ 1.20.0, < 1.20.3≥ 1.21.0, < 1.21.12019-04-09
CVE-2019-3893 [MEDIUM] CWE-732 CVE-2019-3893: In Foreman it was discovered that the delete compute resource operation, when executed from the Fore In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. Versions b
nvd
CVE-2018-16861MEDIUMCVSS 4.8fixed in 1.18.3≥ 1.19.0, < 1.19.1+1 more2018-12-07
CVE-2018-16861 [HIGH] CWE-79 CVE-2018-16861: A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged users.
nvd
CVE-2018-14664MEDIUMCVSS 5.4v1.18.02018-10-12
CVE-2018-14664 [MEDIUM] CWE-79 CVE-2018-14664: A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists d A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.
nvd
CVE-2016-7077MEDIUMCVSS 4.3fixed in 1.14.02018-09-10
CVE-2016-7077 [MEDIUM] CWE-285 CVE-2016-7077: foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper do foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
nvd
CVE-2016-7078MEDIUMCVSS 4.3v1.15.02018-09-10
CVE-2016-7078 [MEDIUM] CWE-285 CVE-2016-7078: foreman before version 1.15.0 is vulnerable to an information leak through organizations and locatio foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editi
nvd
CVE-2016-8639MEDIUMCVSS 5.4fixed in 1.13.02018-08-01
CVE-2016-8639 [MEDIUM] CWE-79 CVE-2016-8639: It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or locatio It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
nvd
CVE-2016-8634MEDIUMCVSS 5.4v1.14.02018-08-01
CVE-2016-8634 [MEDIUM] CWE-79 CVE-2016-8634: A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, i A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS attack if an organization/location with HTML in the name is created, then a us
nvd
CVE-2016-8613MEDIUMCVSS 6.1v1.5.12018-07-31
CVE-2016-8613 [MEDIUM] CWE-79 CVE-2016-8613: A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that contains HTML tags, the console output shown in the web UI does not escape the output causing any HTML or JavaScript to run in the user's browser. The output of the job is stored, making this a stored XSS v
nvd
CVE-2017-7535MEDIUMCVSS 6.1fixed in 1.16.02018-07-26
CVE-2017-7535 [MEDIUM] CWE-79 CVE-2017-7535: foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.
nvd
CVE-2017-2672HIGHCVSS 8.8fixed in 1.152018-06-21
CVE-2017-2672 [MEDIUM] CWE-312 CVE-2017-2672: A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
nvd
CVE-2016-9593HIGHCVSS 8.8fixed in 1.15.02018-04-16
CVE-2016-9593 [MEDIUM] CWE-522 CVE-2016-9593: foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
nvd