Vulnerabilities
Vulnerable Software
Theforeman:  >> Foreman  >> 2.3.4  Security Vulnerabilities
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.
CVSS Score
7.2
EPSS Score
0.039
Published
2021-12-23
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions in FreeIPA if certain conditions are met. The highest threat from this flaw is to system confidentiality. This flaw affects Foreman versions before 2.5.0.
CVSS Score
5.9
EPSS Score
0.004
Published
2021-04-26


Contact Us

Shodan ® - All rights reserved