Vulnerabilities > Theforeman > Foreman > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-7700 Command Injection vulnerability in Theforeman Foreman
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page.
local
low complexity
theforeman CWE-77
6.5
2023-10-03 CVE-2023-4886 A sensitive information exposure vulnerability was found in foreman.
local
low complexity
theforeman redhat
4.4
2022-08-16 CVE-2020-10710 Insufficiently Protected Credentials vulnerability in Theforeman Foreman
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer.
local
low complexity
theforeman CWE-522
4.4
2021-04-26 CVE-2021-3494 Cleartext Transmission of Sensitive Information vulnerability in Theforeman Foreman
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack.
4.3
2019-12-11 CVE-2014-0091 Improper Input Validation vulnerability in Theforeman Foreman
Foreman has improper input validation which could lead to partial Denial of Service
network
low complexity
theforeman CWE-20
5.3
2019-04-09 CVE-2019-3893 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource.
network
low complexity
theforeman redhat CWE-732
4.9
2018-09-10 CVE-2016-7078 Information Exposure vulnerability in Theforeman Foreman 1.15.0
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature.
network
low complexity
theforeman CWE-200
4.3
2018-09-10 CVE-2016-7077 Information Exposure vulnerability in Theforeman Foreman
foreman before 1.14.0 is vulnerable to an information leak.
network
low complexity
theforeman CWE-200
4.3
2018-08-01 CVE-2016-8639 Cross-site Scripting vulnerability in multiple products
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name.
network
low complexity
theforeman redhat CWE-79
5.4
2018-08-01 CVE-2016-8634 Cross-site Scripting vulnerability in Theforeman Foreman 1.14.0
A vulnerability was found in foreman 1.14.0.
network
low complexity
theforeman CWE-79
5.4