Перейти к содержимому
Noroxi

Записи theforeman

98 опубликованных записей вендора theforeman.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 3,1 %
Pre-auth RCE
8
С записью об исправлении
65,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

98 записей
  • CVE-2018-14643
    41В плане

    An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    theforeman · foreman21 сент. 2018 г.

  • CVE-2013-2143
    40В плане

    The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which

    СредняяCVSS 6,5Готовый эксплойтEPSS 48 %

    redhat · network satellite17 апр. 2014 г.

  • CVE-2012-3503
    40В плане

    The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each d

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    theforeman · katello25 авг. 2012 г.

  • CVE-2022-3874
    37Наблюдать

    Os command injection via ct_command and fcct_command

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    redhat · satellite22 сент. 2023 г.

  • CVE-2016-3728
    36Наблюдать

    Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows r

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    theforeman · foreman20 мая 2016 г.

  • CVE-2016-4475
    36Наблюдать

    The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users t

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    theforeman · foreman19 авг. 2016 г.

  • CVE-2018-1097
    36Наблюдать

    A flaw was found in foreman before 1.16.1.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    theforeman · foreman4 апр. 2018 г.

  • CVE-2023-0118
    36Наблюдать

    Foreman: arbitrary code execution through templates

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    theforeman · foreman20 сент. 2023 г.

  • CVE-2023-0462
    36Наблюдать

    Arbitrary code execution through yaml global parameters

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    theforeman · foreman20 сент. 2023 г.

  • CVE-2017-7505
    35Наблюдать

    Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assig

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    theforeman · foreman26 мая 2017 г.

  • CVE-2017-2672
    35Наблюдать

    A flaw was found in foreman before version 1.15 in the logging of adding and registering images.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    theforeman · foreman21 июн. 2018 г.

  • CVE-2016-9593
    35Наблюдать

    foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    theforeman · foreman16 апр. 2018 г.

  • CVE-2021-3590
    35Наблюдать

    A flaw was found in Foreman project.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    theforeman · foreman22 авг. 2022 г.

  • CVE-2026-5136
    35Наблюдать

    Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    redhat · satellite1 июл. 2026 г.

  • CVE-2014-0007
    33Наблюдать

    The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacter

    ВысокаяCVSS 7,5Proof of conceptEPSS 9 %

    theforeman · foreman20 июн. 2014 г.

  • CVE-2015-5152
    32Наблюдать

    Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows re

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    theforeman · foreman17 июл. 2017 г.

  • CVE-2015-5246
    32Наблюдать

    The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors inv

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    theforeman · foreman6 окт. 2017 г.

  • CVE-2021-3589
    32Наблюдать

    An authorization flaw was found in Foreman Ansible.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    theforeman · foreman ansible23 мар. 2022 г.

  • CVE-2017-2667
    32Наблюдать

    Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    theforeman · hammer cli12 мар. 2018 г.

  • CVE-2013-2121
    31Наблюдать

    Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users

    СредняяCVSS 6,0Готовый эксплойтEPSS 25 %

    redhat · openstack31 июл. 2013 г.

  • CVE-2013-0171
    31Наблюдать

    Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    theforeman · foreman8 мая 2014 г.

  • CVE-2013-4182
    31Наблюдать

    app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redhat · openstack16 сент. 2013 г.

  • CVE-2012-5648
    31Наблюдать

    Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified para

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    theforeman · foreman4 апр. 2014 г.

  • CVE-2013-0210
    31Наблюдать

    The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    theforeman · foreman8 мая 2014 г.

  • CVE-2014-3691
    31Наблюдать

    Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which all

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redhat · openstack9 мар. 2015 г.