İçeriğe atla
Noroxi

theforeman kayıtları

theforeman üreticisine ait 98 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
3 · %3,1
Pre-auth RCE
8
Düzeltme kaydı olan
%65,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

98 kayıt
  • CVE-2018-14643
    41Planlayın

    An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.

    KritikCVSS 9,8İstismar yokEPSS %6

    theforeman · foreman21 Eyl 2018

  • CVE-2013-2143
    40Planlayın

    The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which

    OrtaCVSS 6,5SilahlaştırılmışEPSS %48

    redhat · network satellite17 Nis 2014

  • CVE-2012-3503
    40Planlayın

    The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each d

    KritikCVSS 9,8İstismar yokEPSS %3

    theforeman · katello25 Ağu 2012

  • CVE-2022-3874
    37İzleyin

    Os command injection via ct_command and fcct_command

    KritikCVSS 9,1İstismar yokEPSS %2

    redhat · satellite22 Eyl 2023

  • CVE-2016-3728
    36İzleyin

    Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows r

    YüksekCVSS 8,8İstismar yokEPSS %3

    theforeman · foreman20 May 2016

  • CVE-2016-4475
    36İzleyin

    The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users t

    YüksekCVSS 8,8İstismar yokEPSS %3

    theforeman · foreman19 Ağu 2016

  • CVE-2018-1097
    36İzleyin

    A flaw was found in foreman before 1.16.1.

    YüksekCVSS 8,8İstismar yokEPSS %2

    theforeman · foreman4 Nis 2018

  • CVE-2023-0118
    36İzleyin

    Foreman: arbitrary code execution through templates

    KritikCVSS 9,1İstismar yokEPSS %1

    theforeman · foreman20 Eyl 2023

  • CVE-2023-0462
    36İzleyin

    Arbitrary code execution through yaml global parameters

    KritikCVSS 9,1İstismar yokEPSS %1

    theforeman · foreman20 Eyl 2023

  • CVE-2017-7505
    35İzleyin

    Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assig

    YüksekCVSS 8,8İstismar yokEPSS %2

    theforeman · foreman26 May 2017

  • CVE-2017-2672
    35İzleyin

    A flaw was found in foreman before version 1.15 in the logging of adding and registering images.

    YüksekCVSS 8,8İstismar yokEPSS %1

    theforeman · foreman21 Haz 2018

  • CVE-2016-9593
    35İzleyin

    foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging.

    YüksekCVSS 8,8İstismar yokEPSS %1

    theforeman · foreman16 Nis 2018

  • CVE-2021-3590
    35İzleyin

    A flaw was found in Foreman project.

    YüksekCVSS 8,8İstismar yokEPSS %1

    theforeman · foreman22 Ağu 2022

  • CVE-2026-5136
    35İzleyin

    Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation

    YüksekCVSS 8,8İstismar yokEPSS %1

    redhat · satellite1 Tem 2026

  • CVE-2014-0007
    33İzleyin

    The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacter

    YüksekCVSS 7,5Kavram kanıtıEPSS %9

    theforeman · foreman20 Haz 2014

  • CVE-2015-5152
    32İzleyin

    Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows re

    YüksekCVSS 8,1İstismar yokEPSS %2

    theforeman · foreman17 Tem 2017

  • CVE-2015-5246
    32İzleyin

    The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors inv

    YüksekCVSS 8,1İstismar yokEPSS %1

    theforeman · foreman6 Eki 2017

  • CVE-2021-3589
    32İzleyin

    An authorization flaw was found in Foreman Ansible.

    YüksekCVSS 8,0İstismar yokEPSS %1

    theforeman · foreman ansible23 Mar 2022

  • CVE-2017-2667
    32İzleyin

    Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it

    YüksekCVSS 8,1İstismar yokEPSS %1

    theforeman · hammer cli12 Mar 2018

  • CVE-2013-2121
    31İzleyin

    Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users

    OrtaCVSS 6,0SilahlaştırılmışEPSS %25

    redhat · openstack31 Tem 2013

  • CVE-2013-0171
    31İzleyin

    Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.

    YüksekCVSS 7,5İstismar yokEPSS %3

    theforeman · foreman8 May 2014

  • CVE-2013-4182
    31İzleyin

    app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers

    YüksekCVSS 7,5İstismar yokEPSS %2

    redhat · openstack16 Eyl 2013

  • CVE-2012-5648
    31İzleyin

    Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified para

    YüksekCVSS 7,5İstismar yokEPSS %2

    theforeman · foreman4 Nis 2014

  • CVE-2013-0210
    31İzleyin

    The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping

    YüksekCVSS 7,5İstismar yokEPSS %2

    theforeman · foreman8 May 2014

  • CVE-2014-3691
    31İzleyin

    Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which all

    YüksekCVSS 7,5İstismar yokEPSS %2

    redhat · openstack9 Mar 2015