Vulnerabilities > Theforeman > Foreman > Low

DATE CVE VULNERABILITY TITLE RISK
2021-06-03 CVE-2021-3469 Incorrect Authorization vulnerability in Theforeman Foreman
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw.
3.5
2018-12-07 CVE-2018-16861 Cross-site Scripting vulnerability in Theforeman Foreman
A cross-site scripting (XSS) flaw was found in the foreman component of satellite.
network
theforeman CWE-79
3.5
2018-10-12 CVE-2018-14664 Cross-site Scripting vulnerability in Theforeman Foreman 1.18.0
A flaw was found in foreman from versions 1.18.
network
theforeman CWE-79
3.5
2016-08-19 CVE-2016-5390 Information Exposure vulnerability in Theforeman Foreman
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.
3.5
2014-05-08 CVE-2012-5477 Permissions, Privileges, and Access Controls vulnerability in Theforeman Foreman
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
local
low complexity
theforeman CWE-264
3.6