theforeman
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting theforeman.
- CVE-2024-7700Foreman: command injection in "host init config" template via "install packages" field on foreman6.5
- CVE-2023-4886Foreman: world readable file containing secrets6.7
- CVE-2022-3874Os command injection via ct_command and fcct_command8.0
- CVE-2023-0462Arbitrary code execution through yaml global parameters8.0
- CVE-2023-0118Foreman: arbitrary code execution through templates9.1
- CVE-2021-20260A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulne...7.8
- CVE-2021-3590A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is ...8.8
- CVE-2020-10710A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges...4.4
- CVE-2021-3456An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw a...7.1
- CVE-2021-20290An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This fl...6.1
- CVE-2021-3589An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from...8.0
- CVE-2021-3584A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injec...7.2
- CVE-2021-20259A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from thi...7.8
- CVE-2021-3469Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certi...5.4
- CVE-2020-10716A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Inv...6.5