theforeman kayıtları
theforeman üreticisine ait 98 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %3,1
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %65,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-264 Permissions, Privileges, and Access Controls9
- CWE-863 Incorrect Authorization6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-284 Improper Access Control4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
98 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2018-14643İstismar yok | An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.theforeman · foreman · CWE-592 | Kritik9,8 | — | %6,1 | 21 Eyl 2018 |
40Planlayın | CVE-2013-2143Silahlaştırılmış | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, whichredhat · network satellite · CWE-20 | Orta6,5 | — | %48,2 | 17 Nis 2014 |
40Planlayın | CVE-2012-3503İstismar yok | The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each dtheforeman · katello · CWE-798 | Kritik9,8 | — | %3,0 | 25 Ağu 2012 |
37İzleyin | CVE-2022-3874İstismar yok | Os command injection via ct_command and fcct_commandredhat · satellite · CWE-78 | Kritik9,1 | — | %2,2 | 22 Eyl 2023 |
36İzleyin | CVE-2016-3728İstismar yok | Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows rtheforeman · foreman · CWE-284 | Yüksek8,8 | — | %2,8 | 20 May 2016 |
36İzleyin | CVE-2016-4475İstismar yok | The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users ttheforeman · foreman · CWE-254 | Yüksek8,8 | — | %2,7 | 19 Ağu 2016 |
36İzleyin | CVE-2018-1097İstismar yok | A flaw was found in foreman before 1.16.1.theforeman · foreman · CWE-200 | Yüksek8,8 | — | %1,7 | 4 Nis 2018 |
36İzleyin | CVE-2023-0118İstismar yok | Foreman: arbitrary code execution through templatestheforeman · foreman · CWE-78 | Kritik9,1 | — | %1,4 | 20 Eyl 2023 |
36İzleyin | CVE-2023-0462İstismar yok | Arbitrary code execution through yaml global parameterstheforeman · foreman · CWE-94 | Kritik9,1 | — | %1,0 | 20 Eyl 2023 |
35İzleyin | CVE-2017-7505İstismar yok | Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigtheforeman · foreman · CWE-863 | Yüksek8,8 | — | %1,6 | 26 May 2017 |
35İzleyin | CVE-2017-2672İstismar yok | A flaw was found in foreman before version 1.15 in the logging of adding and registering images.theforeman · foreman · CWE-312 | Yüksek8,8 | — | %1,2 | 21 Haz 2018 |
35İzleyin | CVE-2016-9593İstismar yok | foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging.theforeman · foreman · CWE-522 | Yüksek8,8 | — | %1,0 | 16 Nis 2018 |
35İzleyin | CVE-2021-3590İstismar yok | A flaw was found in Foreman project.theforeman · foreman · CWE-200 | Yüksek8,8 | — | %0,7 | 22 Ağu 2022 |
35İzleyin | CVE-2026-5136İstismar yok | Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulationredhat · satellite · CWE-266 | Yüksek8,8 | — | %0,6 | 1 Tem 2026 |
33İzleyin | CVE-2014-0007Kavram kanıtı | The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharactertheforeman · foreman | Yüksek7,5 | — | %9,0 | 20 Haz 2014 |
32İzleyin | CVE-2015-5152İstismar yok | Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows retheforeman · foreman · CWE-200 | Yüksek8,1 | — | %1,5 | 17 Tem 2017 |
32İzleyin | CVE-2015-5246İstismar yok | The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors invtheforeman · foreman · CWE-254 | Yüksek8,1 | — | %1,4 | 6 Eki 2017 |
32İzleyin | CVE-2021-3589İstismar yok | An authorization flaw was found in Foreman Ansible.theforeman · foreman ansible · CWE-306 | Yüksek8,0 | — | %1,0 | 23 Mar 2022 |
32İzleyin | CVE-2017-2667İstismar yok | Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable ittheforeman · hammer cli · CWE-345 | Yüksek8,1 | — | %0,7 | 12 Mar 2018 |
31İzleyin | CVE-2013-2121Silahlaştırılmış | Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users redhat · openstack · CWE-94 | Orta6,0 | — | %24,8 | 31 Tem 2013 |
31İzleyin | CVE-2013-0171İstismar yok | Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.theforeman · foreman · CWE-94 | Yüksek7,5 | — | %3,0 | 8 May 2014 |
31İzleyin | CVE-2013-4182İstismar yok | app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackersredhat · openstack · CWE-264 | Yüksek7,5 | — | %2,4 | 16 Eyl 2013 |
31İzleyin | CVE-2012-5648İstismar yok | Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified paratheforeman · foreman · CWE-89 | Yüksek7,5 | — | %2,1 | 4 Nis 2014 |
31İzleyin | CVE-2013-0210İstismar yok | The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escapingtheforeman · foreman · CWE-94 | Yüksek7,5 | — | %1,9 | 8 May 2014 |
31İzleyin | CVE-2014-3691İstismar yok | Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allredhat · openstack · CWE-310 | Yüksek7,5 | — | %1,7 | 9 Mar 2015 |
- CVE-2018-1464341Planlayın
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.
KritikCVSS 9,8İstismar yokEPSS %6theforeman · foreman21 Eyl 2018
- CVE-2013-214340Planlayın
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which
OrtaCVSS 6,5SilahlaştırılmışEPSS %48redhat · network satellite17 Nis 2014
- CVE-2012-350340Planlayın
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each d
KritikCVSS 9,8İstismar yokEPSS %3theforeman · katello25 Ağu 2012
- CVE-2022-387437İzleyin
Os command injection via ct_command and fcct_command
KritikCVSS 9,1İstismar yokEPSS %2redhat · satellite22 Eyl 2023
- CVE-2016-372836İzleyin
Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows r
YüksekCVSS 8,8İstismar yokEPSS %3theforeman · foreman20 May 2016
- CVE-2016-447536İzleyin
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users t
YüksekCVSS 8,8İstismar yokEPSS %3theforeman · foreman19 Ağu 2016
- CVE-2018-109736İzleyin
A flaw was found in foreman before 1.16.1.
YüksekCVSS 8,8İstismar yokEPSS %2theforeman · foreman4 Nis 2018
- CVE-2023-011836İzleyin
Foreman: arbitrary code execution through templates
KritikCVSS 9,1İstismar yokEPSS %1theforeman · foreman20 Eyl 2023
- CVE-2023-046236İzleyin
Arbitrary code execution through yaml global parameters
KritikCVSS 9,1İstismar yokEPSS %1theforeman · foreman20 Eyl 2023
- CVE-2017-750535İzleyin
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assig
YüksekCVSS 8,8İstismar yokEPSS %2theforeman · foreman26 May 2017
- CVE-2017-267235İzleyin
A flaw was found in foreman before version 1.15 in the logging of adding and registering images.
YüksekCVSS 8,8İstismar yokEPSS %1theforeman · foreman21 Haz 2018
- CVE-2016-959335İzleyin
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging.
YüksekCVSS 8,8İstismar yokEPSS %1theforeman · foreman16 Nis 2018
- CVE-2021-359035İzleyin
A flaw was found in Foreman project.
YüksekCVSS 8,8İstismar yokEPSS %1theforeman · foreman22 Ağu 2022
- CVE-2026-513635İzleyin
Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation
YüksekCVSS 8,8İstismar yokEPSS %1redhat · satellite1 Tem 2026
- CVE-2014-000733İzleyin
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacter
YüksekCVSS 7,5Kavram kanıtıEPSS %9theforeman · foreman20 Haz 2014
- CVE-2015-515232İzleyin
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows re
YüksekCVSS 8,1İstismar yokEPSS %2theforeman · foreman17 Tem 2017
- CVE-2015-524632İzleyin
The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors inv
YüksekCVSS 8,1İstismar yokEPSS %1theforeman · foreman6 Eki 2017
- CVE-2021-358932İzleyin
An authorization flaw was found in Foreman Ansible.
YüksekCVSS 8,0İstismar yokEPSS %1theforeman · foreman ansible23 Mar 2022
- CVE-2017-266732İzleyin
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it
YüksekCVSS 8,1İstismar yokEPSS %1theforeman · hammer cli12 Mar 2018
- CVE-2013-212131İzleyin
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users
OrtaCVSS 6,0SilahlaştırılmışEPSS %25redhat · openstack31 Tem 2013
- CVE-2013-017131İzleyin
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
YüksekCVSS 7,5İstismar yokEPSS %3theforeman · foreman8 May 2014
- CVE-2013-418231İzleyin
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers
YüksekCVSS 7,5İstismar yokEPSS %2redhat · openstack16 Eyl 2013
- CVE-2012-564831İzleyin
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified para
YüksekCVSS 7,5İstismar yokEPSS %2theforeman · foreman4 Nis 2014
- CVE-2013-021031İzleyin
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping
YüksekCVSS 7,5İstismar yokEPSS %2theforeman · foreman8 May 2014
- CVE-2014-369131İzleyin
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which all
YüksekCVSS 7,5İstismar yokEPSS %2redhat · openstack9 Mar 2015