CVE Tools

The-foreman-project

3 CVEs tracked since 2018. Since Aug 2018, none of them reached CISA KEV.

The-foreman-project CVEs per month

Aug 2018 to Aug 2018. Point at a month, or focus the strip and use the arrow keys.
The-foreman-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0830

Products

The products that kept showing up in The-foreman-project's monthly top three, with their CVEs summed over those months.

  1. Foreman21 month
  2. Foreman Katello Plugin11 month

Latest CVEs

The 8 most recently published vulnerabilities affecting The-foreman-project.

  1. CVE-2019-10198An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the c...6.5
  2. CVE-2019-3893In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute reso...4.9
  3. CVE-2018-14623A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak interna...4.3
  4. CVE-2018-16861A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able...7.6
  5. CVE-2017-2662A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not res...4.3
  6. CVE-2016-8639It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to ...6.1
  7. CVE-2016-8634A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render...6.1
  8. CVE-2016-8613A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that contains HTML tags, the console output shown in ...6.4

The record

Peak rank
#129 in Aug 2018
Busiest month shown
Aug 2018, 3 CVEs
Months with a KEV entry
0 since Aug 2018
Monthly snapshots
1 since 2018
The-foreman-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store