Vulnerabilities > Theforeman > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-7700 Command Injection vulnerability in Theforeman Foreman
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page.
local
low complexity
theforeman CWE-77
6.5
2023-10-03 CVE-2023-4886 A sensitive information exposure vulnerability was found in foreman.
local
low complexity
theforeman redhat
4.4
2022-08-16 CVE-2020-10710 Insufficiently Protected Credentials vulnerability in Theforeman Foreman
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer.
local
low complexity
theforeman CWE-522
4.4
2022-03-25 CVE-2021-20290 Incorrect Authorization vulnerability in Theforeman Openscap
An improper authorization handling flaw was found in Foreman.
local
low complexity
theforeman CWE-863
6.1
2021-06-03 CVE-2021-3469 Incorrect Authorization vulnerability in Theforeman Foreman
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw.
network
low complexity
theforeman CWE-863
5.4
2021-05-27 CVE-2020-10716 A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view.
network
low complexity
redhat theforeman
6.5
2021-05-12 CVE-2021-3457 Unspecified vulnerability in Theforeman Smart Proxy Shell Hooks 0.9.0/0.9.1
An improper authorization handling flaw was found in Foreman.
local
low complexity
theforeman
6.1
2021-04-26 CVE-2021-3494 Unspecified vulnerability in Theforeman Foreman
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack.
network
high complexity
theforeman
5.9
2021-04-08 CVE-2021-3413 A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0.
network
low complexity
theforeman redhat
6.3
2019-12-13 CVE-2014-0241 Insufficiently Protected Credentials vulnerability in multiple products
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
local
low complexity
theforeman redhat CWE-522
5.5