Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2016-8639

Disclosure Date: August 01, 2018 (last updated November 08, 2023)
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
0
Attacker Value
Unknown

CVE-2016-9595

Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
0
Attacker Value
Unknown

CVE-2017-2667

Disclosure Date: March 12, 2018 (last updated January 27, 2024)
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.