VendorsTheforemanforeman1.2.3
Vulnerabilities

Theforeman Foreman 1.2.0 release candidate 2 1.2.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-5152
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
Published 2017-07-14 · Modified
8.1EPSS 0.015
CVE-2014-0090
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
Published 2014-05-08 · Modified
6.8EPSS 0.014