cbcvebase.

Theforeman Foreman vulnerabilities

69 known vulnerabilities affecting theforeman/foreman.

Total CVEs
69
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH19MEDIUM47LOW1

Vulnerabilities

Page 4 of 4
CVE-2016-7078P4MEDIUMCVSS 4.3v1.15.02018-09-10
CVE-2016-7078 [MEDIUM] CWE-285 CVE-2016-7078: foreman before version 1.15.0 is vulnerable to an information leak through organizations and locatio foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editi
nvd
CVE-2015-1816P4MEDIUMCVSS 5.0≤ 1.7.32015-08-14
CVE-2015-1816 [MEDIUM] CWE-310 CVE-2015-1816: Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-m Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
nvd
CVE-2014-3653P4MEDIUMCVSS 4.3≤ 1.6.02015-07-06
CVE-2014-3653 [MEDIUM] CWE-79 CVE-2014-3653: Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 al Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.
nvd
CVE-2015-7518P4MEDIUMCVSS 4.3≤ 1.9.32015-12-17
CVE-2015-7518 [MEDIUM] CWE-79 CVE-2015-7518: Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 a Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit forms.
nvd
CVE-2014-3491P4MEDIUMCVSS 4.3≤ 1.4.4v1.4.0+4 more2014-07-01
CVE-2014-3491 [MEDIUM] CWE-79 CVE-2014-3491: Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remot Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes.
nvd
CVE-2014-0089P4MEDIUMCVSS 4.3v1.4.0v1.4.12014-03-27
CVE-2014-0089 [MEDIUM] CWE-79 CVE-2014-0089: Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1. Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.
nvd
CVE-2014-3492P4MEDIUMCVSS 4.3≤ 1.4.4v1.4.0+4 more2014-07-01
CVE-2014-3492 [MEDIUM] CWE-79 CVE-2014-3492: Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 an Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host.
nvd
CVE-2023-4886P4MEDIUMCVSS 4.4fixed in 3.8.02023-10-03
CVE-2023-4886 [MEDIUM] CWE-200 CVE-2023-4886: A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
nvd
CVE-2012-5477P4LOWCVSS 3.6≤ 1.02014-05-08
CVE-2012-5477 [LOW] CWE-264 CVE-2012-5477: The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify file The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
nvd
Theforeman Foreman vulnerabilities | cvebase