Записи theforeman
98 опубликованных записей вендора theforeman.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 3,1 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 65,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-264 Permissions, Privileges, and Access Controls9
- CWE-863 Incorrect Authorization6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-284 Improper Access Control4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
98 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2018-14643Эксплойта нет | An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.theforeman · foreman · CWE-592 | Критическая9,8 | — | 6,1 % | 21 сент. 2018 г. |
40В плане | CVE-2013-2143Готовый эксплойт | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, whichredhat · network satellite · CWE-20 | Средняя6,5 | — | 48,2 % | 17 апр. 2014 г. |
40В плане | CVE-2012-3503Эксплойта нет | The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each dtheforeman · katello · CWE-798 | Критическая9,8 | — | 3,0 % | 25 авг. 2012 г. |
37Наблюдать | CVE-2022-3874Эксплойта нет | Os command injection via ct_command and fcct_commandredhat · satellite · CWE-78 | Критическая9,1 | — | 2,2 % | 22 сент. 2023 г. |
36Наблюдать | CVE-2016-3728Эксплойта нет | Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows rtheforeman · foreman · CWE-284 | Высокая8,8 | — | 2,8 % | 20 мая 2016 г. |
36Наблюдать | CVE-2016-4475Эксплойта нет | The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users ttheforeman · foreman · CWE-254 | Высокая8,8 | — | 2,7 % | 19 авг. 2016 г. |
36Наблюдать | CVE-2018-1097Эксплойта нет | A flaw was found in foreman before 1.16.1.theforeman · foreman · CWE-200 | Высокая8,8 | — | 1,7 % | 4 апр. 2018 г. |
36Наблюдать | CVE-2023-0118Эксплойта нет | Foreman: arbitrary code execution through templatestheforeman · foreman · CWE-78 | Критическая9,1 | — | 1,4 % | 20 сент. 2023 г. |
36Наблюдать | CVE-2023-0462Эксплойта нет | Arbitrary code execution through yaml global parameterstheforeman · foreman · CWE-94 | Критическая9,1 | — | 1,0 % | 20 сент. 2023 г. |
35Наблюдать | CVE-2017-7505Эксплойта нет | Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigtheforeman · foreman · CWE-863 | Высокая8,8 | — | 1,6 % | 26 мая 2017 г. |
35Наблюдать | CVE-2017-2672Эксплойта нет | A flaw was found in foreman before version 1.15 in the logging of adding and registering images.theforeman · foreman · CWE-312 | Высокая8,8 | — | 1,2 % | 21 июн. 2018 г. |
35Наблюдать | CVE-2016-9593Эксплойта нет | foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging.theforeman · foreman · CWE-522 | Высокая8,8 | — | 1,0 % | 16 апр. 2018 г. |
35Наблюдать | CVE-2021-3590Эксплойта нет | A flaw was found in Foreman project.theforeman · foreman · CWE-200 | Высокая8,8 | — | 0,7 % | 22 авг. 2022 г. |
35Наблюдать | CVE-2026-5136Эксплойта нет | Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulationredhat · satellite · CWE-266 | Высокая8,8 | — | 0,6 % | 1 июл. 2026 г. |
33Наблюдать | CVE-2014-0007Proof of concept | The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharactertheforeman · foreman | Высокая7,5 | — | 9,0 % | 20 июн. 2014 г. |
32Наблюдать | CVE-2015-5152Эксплойта нет | Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows retheforeman · foreman · CWE-200 | Высокая8,1 | — | 1,5 % | 17 июл. 2017 г. |
32Наблюдать | CVE-2015-5246Эксплойта нет | The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors invtheforeman · foreman · CWE-254 | Высокая8,1 | — | 1,4 % | 6 окт. 2017 г. |
32Наблюдать | CVE-2021-3589Эксплойта нет | An authorization flaw was found in Foreman Ansible.theforeman · foreman ansible · CWE-306 | Высокая8,0 | — | 1,0 % | 23 мар. 2022 г. |
32Наблюдать | CVE-2017-2667Эксплойта нет | Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable ittheforeman · hammer cli · CWE-345 | Высокая8,1 | — | 0,7 % | 12 мар. 2018 г. |
31Наблюдать | CVE-2013-2121Готовый эксплойт | Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users redhat · openstack · CWE-94 | Средняя6,0 | — | 24,8 % | 31 июл. 2013 г. |
31Наблюдать | CVE-2013-0171Эксплойта нет | Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.theforeman · foreman · CWE-94 | Высокая7,5 | — | 3,0 % | 8 мая 2014 г. |
31Наблюдать | CVE-2013-4182Эксплойта нет | app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackersredhat · openstack · CWE-264 | Высокая7,5 | — | 2,4 % | 16 сент. 2013 г. |
31Наблюдать | CVE-2012-5648Эксплойта нет | Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified paratheforeman · foreman · CWE-89 | Высокая7,5 | — | 2,1 % | 4 апр. 2014 г. |
31Наблюдать | CVE-2013-0210Эксплойта нет | The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escapingtheforeman · foreman · CWE-94 | Высокая7,5 | — | 1,9 % | 8 мая 2014 г. |
31Наблюдать | CVE-2014-3691Эксплойта нет | Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allredhat · openstack · CWE-310 | Высокая7,5 | — | 1,7 % | 9 мар. 2015 г. |
- CVE-2018-1464341В плане
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %theforeman · foreman21 сент. 2018 г.
- CVE-2013-214340В плане
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which
СредняяCVSS 6,5Готовый эксплойтEPSS 48 %redhat · network satellite17 апр. 2014 г.
- CVE-2012-350340В плане
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each d
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %theforeman · katello25 авг. 2012 г.
- CVE-2022-387437Наблюдать
Os command injection via ct_command and fcct_command
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %redhat · satellite22 сент. 2023 г.
- CVE-2016-372836Наблюдать
Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows r
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %theforeman · foreman20 мая 2016 г.
- CVE-2016-447536Наблюдать
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users t
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %theforeman · foreman19 авг. 2016 г.
- CVE-2018-109736Наблюдать
A flaw was found in foreman before 1.16.1.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %theforeman · foreman4 апр. 2018 г.
- CVE-2023-011836Наблюдать
Foreman: arbitrary code execution through templates
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %theforeman · foreman20 сент. 2023 г.
- CVE-2023-046236Наблюдать
Arbitrary code execution through yaml global parameters
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %theforeman · foreman20 сент. 2023 г.
- CVE-2017-750535Наблюдать
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assig
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %theforeman · foreman26 мая 2017 г.
- CVE-2017-267235Наблюдать
A flaw was found in foreman before version 1.15 in the logging of adding and registering images.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %theforeman · foreman21 июн. 2018 г.
- CVE-2016-959335Наблюдать
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %theforeman · foreman16 апр. 2018 г.
- CVE-2021-359035Наблюдать
A flaw was found in Foreman project.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %theforeman · foreman22 авг. 2022 г.
- CVE-2026-513635Наблюдать
Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %redhat · satellite1 июл. 2026 г.
- CVE-2014-000733Наблюдать
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacter
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %theforeman · foreman20 июн. 2014 г.
- CVE-2015-515232Наблюдать
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows re
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %theforeman · foreman17 июл. 2017 г.
- CVE-2015-524632Наблюдать
The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors inv
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %theforeman · foreman6 окт. 2017 г.
- CVE-2021-358932Наблюдать
An authorization flaw was found in Foreman Ansible.
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %theforeman · foreman ansible23 мар. 2022 г.
- CVE-2017-266732Наблюдать
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %theforeman · hammer cli12 мар. 2018 г.
- CVE-2013-212131Наблюдать
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users
СредняяCVSS 6,0Готовый эксплойтEPSS 25 %redhat · openstack31 июл. 2013 г.
- CVE-2013-017131Наблюдать
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %theforeman · foreman8 мая 2014 г.
- CVE-2013-418231Наблюдать
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redhat · openstack16 сент. 2013 г.
- CVE-2012-564831Наблюдать
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified para
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %theforeman · foreman4 апр. 2014 г.
- CVE-2013-021031Наблюдать
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %theforeman · foreman8 мая 2014 г.
- CVE-2014-369131Наблюдать
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which all
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redhat · openstack9 мар. 2015 г.