Vulnerabilities
Vulnerable Software
Theforeman:  Security Vulnerabilities
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
CVSS Score
5.0
EPSS Score
0.015
Published
2014-05-08
Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.
CVSS Score
1.9
EPSS Score
0.003
Published
2014-05-08
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
CVSS Score
6.8
EPSS Score
0.014
Published
2014-05-08
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
CVSS Score
3.6
EPSS Score
0.003
Published
2014-05-08
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
CVSS Score
7.5
EPSS Score
0.03
Published
2014-05-08
Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attack.
CVSS Score
5.0
EPSS Score
0.011
Published
2014-05-08
The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
CVSS Score
5.0
EPSS Score
0.017
Published
2014-05-08
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
CVSS Score
6.5
EPSS Score
0.011
Published
2014-05-08
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
CVSS Score
7.5
EPSS Score
0.019
Published
2014-05-08
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
CVSS Score
6.5
EPSS Score
0.482
Published
2014-04-17


Contact Us

Shodan ® - All rights reserved