Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2015-5152
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2014-0090
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
0
Attacker Value
Unknown
CVE-2013-4386
Disclosure Date: November 20, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
0