VendorsTheforemanforemanany version
Vulnerabilities

Theforeman Foreman 1.2.0 release candidate 2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

66CVEs
CVE-2018-14643
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.
Published 2018-09-21 · Modified
10.0EPSS 0.061
CVE-2022-3874
Os command injection via ct_command and fcct_command
Published 2023-09-22 · Modified
9.1EPSS 0.022
CVE-2023-0118
Foreman: arbitrary code execution through templates
Published 2023-09-20 · Modified
9.1EPSS 0.014
CVE-2023-0462
Arbitrary code execution through yaml global parameters
Published 2023-09-20 · Modified
9.1EPSS 0.010
CVE-2021-3584
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.
Published 2021-12-23 · Modified
9.0EPSS 0.039
CVE-2016-4475
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.
Published 2016-08-19 · Modified
8.8EPSS 0.027
CVE-2018-1097
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
Published 2018-04-04 · Modified
8.8EPSS 0.017
CVE-2017-2672
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
Published 2018-06-21 · Modified
8.8EPSS 0.012
CVE-2016-9593
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
Published 2018-04-16 · Modified
8.8EPSS 0.010
CVE-2021-3590
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2022-08-22 · Modified
8.8EPSS 0.007
CVE-2026-5136
Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation
Published 2026-07-01 · Analyzed
8.8EPSS 0.006
CVE-2026-12112
Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse
Published 2026-06-23 · Modified
7.8EPSS 0.002
CVE-2021-20260
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2022-08-26 · Modified
7.8EPSS 0.002
CVE-2018-16861
A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Foreman before 1.18.3, 1.19.1, and 1.20.0 are vulnerable.
Published 2018-12-07 · Modified
7.6EPSS 0.009
CVE-2014-0007
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
Published 2014-06-20 · Modified
7.51 PoCEPSS 0.090
CVE-2013-0171
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
Published 2014-05-08 · Modified
7.5EPSS 0.030
CVE-2013-4182
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
Published 2013-09-16 · Modified
7.5EPSS 0.024
CVE-2012-5648
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
Published 2014-04-04 · Modified
7.5EPSS 0.021
CVE-2013-0210
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
Published 2014-05-08 · Modified
7.5EPSS 0.019
CVE-2014-3691
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.
Published 2015-03-09 · Modified
7.5EPSS 0.017
CVE-2013-4386
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
Published 2013-11-19 · Modified
7.5EPSS 0.012
CVE-2014-8183
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
Published 2019-08-01 · Modified
7.4EPSS 0.007
CVE-2014-0090
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
Published 2014-05-08 · Modified
6.8EPSS 0.014
CVE-2023-4886
Foreman: world readable file containing secrets
Published 2023-10-03 · Modified
6.7EPSS 0.003
CVE-2018-1096
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
Published 2018-04-05 · Modified
6.5EPSS 0.013
CVE-2016-2100
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
Published 2016-05-20 · Modified
6.5EPSS 0.012
CVE-2013-0187
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
Published 2014-05-08 · Modified
6.5EPSS 0.011
CVE-2024-7700
Foreman: command injection in "host init config" template via "install packages" field on foreman
Published 2024-08-12 · Analyzed
6.5EPSS 0.008
CVE-2026-5142
Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass
Published 2026-07-01 · Analyzed
6.5EPSS 0.004
CVE-2026-5135
Foreman: foreman: unauthorized modification of host configurations via broken access control
Published 2026-07-01 · Analyzed
6.5EPSS 0.004
CVE-2025-9572
Foreman: satellite: graphql api permission bypass leads to information disclosure
Published 2026-02-27 · Modified
6.5EPSS 0.003
CVE-2014-4507
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
Published 2014-06-20 · Modified
6.4EPSS 0.024
CVE-2026-9073
Foreman-mcp-server: mcp server: insecure sensitive http header sanitization
Published 2026-06-23 · Modified
6.2EPSS 0.002
CVE-2016-6319
Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugins, allows remote attackers to inject arbitrary web script or HTML via the label parameter.
Published 2016-08-19 · Modified
6.1EPSS 0.020
CVE-2017-7535
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.
Published 2018-07-26 · Modified
6.1EPSS 0.015
CVE-2016-8639
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
Published 2018-08-01 · Modified
6.1EPSS 0.012
CVE-2017-15100
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.
Published 2017-11-27 · Modified
6.1EPSS 0.011
CVE-2013-2121
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
Published 2013-07-31 · Modified
6.01 PoCEPSS 0.248
CVE-2013-2113
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
Published 2013-07-31 · Modified
6.01 PoCEPSS 0.209
CVE-2015-3235
Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
Published 2015-08-14 · Modified
6.0EPSS 0.016
1 / 2Next →