Show filters
90 Total Results
Displaying 51-60 of 90
Sort by:
Attacker Value
Unknown

CVE-2015-5152

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
0
Attacker Value
Unknown

CVE-2017-7505

Disclosure Date: May 26, 2017 (last updated November 26, 2024)
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
0
Attacker Value
Unknown

CVE-2016-4995

Disclosure Date: August 19, 2016 (last updated November 25, 2024)
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
0
Attacker Value
Unknown

CVE-2016-4475

Disclosure Date: August 19, 2016 (last updated November 25, 2024)
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-6320

Disclosure Date: August 19, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form.
0
Attacker Value
Unknown

CVE-2016-6319

Disclosure Date: August 19, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugins, allows remote attackers to inject arbitrary web script or HTML via the label parameter.
0
Attacker Value
Unknown

CVE-2016-5390

Disclosure Date: August 19, 2016 (last updated November 25, 2024)
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.
0
Attacker Value
Unknown

CVE-2016-4451

Disclosure Date: August 19, 2016 (last updated November 25, 2024)
The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.
0
Attacker Value
Unknown

CVE-2016-3728

Disclosure Date: May 20, 2016 (last updated November 25, 2024)
Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/.
0
Attacker Value
Unknown

CVE-2016-2100

Disclosure Date: May 20, 2016 (last updated November 25, 2024)
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
0