Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2012-6685
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
Nokogiri before 1.5.4 is vulnerable to XXE attacks
0
Attacker Value
Unknown
CVE-2014-3691
Disclosure Date: March 09, 2015 (last updated October 05, 2023)
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.
0
Attacker Value
Unknown
CVE-2013-4386
Disclosure Date: November 20, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
0
Attacker Value
Unknown
CVE-2013-4180
Disclosure Date: September 16, 2013 (last updated October 05, 2023)
The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.
0
Attacker Value
Unknown
CVE-2013-4182
Disclosure Date: September 16, 2013 (last updated October 05, 2023)
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
0
Attacker Value
Unknown
CVE-2013-2121
Disclosure Date: July 31, 2013 (last updated October 05, 2023)
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
0
Attacker Value
Unknown
CVE-2013-2113
Disclosure Date: July 31, 2013 (last updated October 05, 2023)
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
0