VendorsTheforemanforeman1.2.1
Vulnerabilities

Theforeman Foreman 1.2.0 release candidate 2 1.2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2015-5152
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
Published 2017-07-14 · Modified
8.1EPSS 0.015
CVE-2013-4386
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
Published 2013-11-19 · Modified
7.5EPSS 0.012
CVE-2014-0090
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
Published 2014-05-08 · Modified
6.8EPSS 0.014