VendorsTheforemanforeman1.4.4
Vulnerabilities

Theforeman Foreman 1.2.0 release candidate 2 1.4.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-5152
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
Published 2017-07-14 · Modified
8.1EPSS 0.015
CVE-2014-0192
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
Published 2014-05-08 · Modified
5.0EPSS 0.015