Vulnerabilities
Vulnerable Software
Theforeman:  >> Foreman  >> 0.1  Security Vulnerabilities
The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
CVSS Score
5.0
EPSS Score
0.003
Published
2014-05-08
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
CVSS Score
6.5
EPSS Score
0.004
Published
2014-05-08
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
CVSS Score
7.5
EPSS Score
0.008
Published
2014-05-08
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
CVSS Score
7.5
EPSS Score
0.006
Published
2014-04-04
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
CVSS Score
7.5
EPSS Score
0.004
Published
2013-11-20
The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.
CVSS Score
5.0
EPSS Score
0.005
Published
2013-09-16
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
CVSS Score
7.5
EPSS Score
0.007
Published
2013-09-16


Contact Us

Shodan ® - All rights reserved