Foreman
This hub aggregates every CVE we track for Foreman, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
72
CVEs tracked
2
Critical
21
High
0
In CISA KEV
Severity distribution
MEDIUM48HIGH21CRITICAL2LOW1
Monthly trend
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Foreman.
- CVE-2025-9572Foreman: satellite: graphql api permission bypass leads to information disclosure5.0
- CVE-2025-10622Foreman: os command injection via ct_location and fcct_location parameters8.0
- CVE-2024-7700Foreman: command injection in "host init config" template via "install packages" field on foreman6.5
- CVE-2023-4886Foreman: world readable file containing secrets6.7
- CVE-2022-3874Os command injection via ct_command and fcct_command8.0
- CVE-2023-0462Arbitrary code execution through yaml global parameters8.0
- CVE-2023-0118Foreman: arbitrary code execution through templates9.1
- CVE-2021-20260A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulne...7.8
- CVE-2021-3590A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is ...8.8
- CVE-2020-10710A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges...4.4
- CVE-2021-3584A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injec...7.2
- CVE-2021-3469Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certi...5.4
- CVE-2021-3494A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does no...5.9
- CVE-2014-0091Foreman has improper input validation which could lead to partial Denial of Service5.3
- CVE-2014-8183It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resour...7.4
Product normalization is registry-driven with AI assist and human review. How it works