Skip to main content

Vendor/product archive

theforeman / foreman CVEs

Beta · best-effort

77 CVEs tagged to theforeman / foreman2 Critical, 22 High, 52 Medium, 1 Low, 0 Unrated.

CVE-2026-13316

Published Jun 30, 2026

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata s…

CVSS 4.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9073

Published Jun 23, 2026

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs sessi…

CVSS 6.2 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-12112

Published Jun 23, 2026

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to a…

CVSS 7.8 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2024-7700

Published Aug 12, 2024

A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4886

Published Oct 3, 2023

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were fou…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3874

Published Sep 22, 2023

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0462

Published Sep 20, 2023

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20260

Published Aug 26, 2022

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest thre…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10710

Published Aug 16, 2022

A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficient…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3584

Published Dec 23, 2021

A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and per…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3469

Published Jun 3, 2021

Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enabl…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3494

Published Apr 26, 2021

A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman s…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0091

Published Dec 11, 2019

Foreman has improper input validation which could lead to partial Denial of Service

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8183

Published Aug 1, 2019

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowl…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3893

Published Apr 9, 2019

In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the aff…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16861

Published Dec 7, 2018

A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Admini…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14664

Published Oct 12, 2018

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a use…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14643

Published Sep 21, 2018

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on mach…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 77 CVEsPage 1 of 4