Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2016-8639
Disclosure Date: August 01, 2018 (last updated November 08, 2023)
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
0
Attacker Value
Unknown
CVE-2016-9595
Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
0
Attacker Value
Unknown
CVE-2017-2667
Disclosure Date: March 12, 2018 (last updated January 27, 2024)
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
0