Show filters
90 Total Results
Displaying 81-90 of 90
Sort by:
Attacker Value
Unknown

CVE-2013-0210

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
0
Attacker Value
Unknown

CVE-2013-2143

Disclosure Date: April 17, 2014 (last updated October 05, 2023)
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
0
Attacker Value
Unknown

CVE-2012-5648

Disclosure Date: April 04, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
0
Attacker Value
Unknown

CVE-2014-0089

Disclosure Date: March 27, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.
0
Attacker Value
Unknown

CVE-2013-4386

Disclosure Date: November 20, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
0
Attacker Value
Unknown

CVE-2013-4180

Disclosure Date: September 16, 2013 (last updated October 05, 2023)
The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.
0
Attacker Value
Unknown

CVE-2013-4182

Disclosure Date: September 16, 2013 (last updated October 05, 2023)
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
0
Attacker Value
Unknown

CVE-2013-2121

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
0
Attacker Value
Unknown

CVE-2013-2113

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
0
Attacker Value
Unknown

CVE-2012-3503

Disclosure Date: August 25, 2012 (last updated February 14, 2024)
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.