foreman vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the foreman package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
Arbitrary Command Injection

*
  • M
Key Exchange without Entity Authentication

*
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:2.1.2.19-1.el7sat
  • H
Directory Traversal

<0:2.1.2.19-1.el7sat
  • H
Incorrect Default Permissions

<0:2.1.2.19-1.el7sat
  • H
Improper Validation of Certificate with Host Mismatch

<0:2.1.2.19-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • H
HTTP Request Smuggling

<0:2.1.2.19-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • H
Eval Injection

<0:2.1.2.19-1.el7sat
  • H
HTTP Response Splitting

<0:2.1.2.19-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • H
Improperly Implemented Security Check for Standard

<0:2.1.2.19-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • H
CVE-2018-3258

<0:2.1.2.19-1.el7sat
  • H
Missing Authorization

<0:2.1.2.19-1.el7sat
  • M
Information Exposure

*
  • H
OS Command Injection

*
  • M
Information Exposure Through Log Files

<0:1.20.1.34-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.20.1.34-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.20.1.34-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.20.1.34-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Missing Authorization

<0:2.3.1.20-1.el7sat
  • M
Missing Authorization

<0:2.3.1.20-1.el7sat
  • M
Information Exposure Through Log Files

<0:2.3.1.20-1.el7sat
  • M
Information Exposure Through Log Files

<0:2.3.1.20-1.el7sat
  • H
Information Exposure

<0:1.18.0.37-1.el7sat
  • H
SQL Injection

<0:1.18.0.37-1.el7sat
  • H
Information Exposure

<0:1.18.0.37-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.18.0.37-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.18.0.37-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.18.0.37-1.el7sat
  • H
XML External Entity (XXE) Injection

<0:1.18.0.37-1.el7sat
  • H
Information Exposure

<0:1.18.0.37-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • H
Use of a Broken or Risky Cryptographic Algorithm

<0:1.18.0.37-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • H
Improper Access Control

<0:1.18.0.37-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.18.0.37-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.18.0.37-1.el7sat
  • H
Information Exposure

<0:1.18.0.37-1.el7sat
  • M
Cross-site Scripting (XSS)

*
  • M
Cleartext Transmission of Sensitive Information

<0:2.5.2.17-2.el7sat
  • M
Cleartext Transmission of Sensitive Information

<0:2.5.2.17-2.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • M
Open Redirect

<0:2.5.2.17-2.el7sat
  • M
Open Redirect

<0:2.5.2.17-2.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • H
Covert Timing Channel

<0:1.18.0.37-1.el7sat
  • H
Incorrect Calculation

<0:1.18.0.37-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.18.0.37-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.18.0.37-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.18.0.37-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Directory Traversal

<0:1.20.1.34-1.el7sat
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

<0:1.18.0.37-1.el7sat
  • H
Improper Certificate Validation

<0:1.18.0.37-1.el7sat
  • H
OS Command Injection

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

<0:1.11.0.53-1.el7sat
  • H
SQL Injection

<0:1.15.6.34-1.el7sat
  • H
Cleartext Storage of Sensitive Information

<0:1.15.6.34-1.el7sat
  • H
Insufficient Verification of Data Authenticity

<0:1.15.6.34-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.15.6.34-1.el7sat
  • H
Improper Input Validation

<0:1.15.6.34-1.el7sat
  • H
Insecure Temporary File

<0:1.15.6.34-1.el7sat
  • H
Insufficiently Protected Credentials

<0:1.15.6.34-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.15.6.34-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.15.6.34-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.15.6.34-1.el7sat
  • H
Improper Authorization

<0:1.15.6.34-1.el7sat
  • H
Improper Authorization

<0:1.15.6.34-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.15.6.34-1.el7sat
  • H
Information Exposure Through Log Files

<0:1.15.6.34-1.el7sat
  • H
Information Exposure

<0:1.15.6.34-1.el7sat
  • H
Improper Access Control

<0:1.15.6.34-1.el7sat
  • H
Use of Insufficiently Random Values

<0:1.15.6.34-1.el7sat
  • H
Incorrect Permission Assignment for Critical Resource

<0:1.15.6.34-1.el7sat
  • H
Improper Input Validation

<0:1.15.6.34-1.el7sat
  • H
Improper Access Control

<0:1.15.6.34-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.15.6.34-1.el7sat
  • H
Arbitrary Code Injection

*
  • M
Information Exposure

*
  • M
Incorrect Authorization

*
  • M
Improper Input Validation

<0:1.11.0.49-1.el7sat
  • M
Incorrect Permission Assignment for Critical Resource

<0:1.11.0.49-1.el7sat
  • M
Race Condition

<0:1.11.0.49-1.el7sat
  • M
Insecure Temporary File

<0:1.11.0.49-1.el7sat
  • M
Incorrect Permission Assignment for Critical Resource

<0:1.11.0.49-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.11.0.49-1.el7sat
  • M
Cleartext Transmission of Sensitive Information

<0:1.11.0.49-1.el7sat
  • M
Improper Authorization

*
  • M
Improper Access Control

<0:1.11.0.51-1.el7sat
  • M
Incorrect Permission Assignment for Critical Resource

<0:1.22.0.32-1.el7sat
  • M
Cleartext Storage of Sensitive Information

<0:1.22.0.32-1.el7sat
  • M
Improper Authentication

<0:1.22.0.32-1.el7sat
  • H
Information Exposure

<0:1.18.0.37-1.el7sat
  • M
Insufficiently Protected Credentials

<0:1.24.1.25-1.el7sat
  • H
Improper Authorization

<0:1.24.1.21-1.el7sat
  • H
Cleartext Transmission of Sensitive Information

<0:1.24.1.21-1.el7sat
  • H
Improper Certificate Validation

<0:1.24.1.21-1.el7sat
  • H
Insufficiently Protected Credentials

<0:1.24.1.28-3.el7sat
  • H
Insufficiently Protected Credentials

<0:2.1.2.19-1.el7sat
  • H
Insufficiently Protected Credentials

<0:2.1.2.19-1.el7sat
  • H
Improper Input Validation

<0:1.18.0.37-1.el7sat
  • H
Improper Input Validation

<0:1.18.0.37-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.18.0.37-1.el7sat
  • H
Improper Authentication

<0:1.24.1.32-1.el7sat
  • H
Improper Authentication

<0:2.1.2.19-1.el7sat
  • H
Improper Authentication

<0:2.1.2.19-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.22.0.32-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • H
Information Exposure

<0:2.1.2.19-1.el7sat
  • H
Incorrect Default Permissions

<0:2.1.2.19-1.el7sat
  • M
SQL Injection

<0:2.3.1.20-1.el7sat
  • M
SQL Injection

<0:2.3.1.20-1.el7sat
  • H
Improperly Implemented Security Check for Standard

<0:2.1.2.19-1.el7sat
  • M
Unchecked Error Condition

<0:2.5.2.17-2.el7sat
  • M
Unchecked Error Condition

<0:2.5.2.17-2.el7sat
  • M
Improper Verification of Cryptographic Signature

<0:2.5.2.17-2.el7sat
  • M
Improper Verification of Cryptographic Signature

<0:2.5.2.17-2.el7sat
  • M
Directory Traversal

<0:2.5.2.17-2.el7sat
  • M
Directory Traversal

<0:2.5.2.17-2.el7sat
  • M
Directory Traversal

<0:2.5.2.17-2.el7sat
  • M
Directory Traversal

<0:2.5.2.17-2.el7sat
  • M
Server-Side Request Forgery (SSRF)

<0:2.5.2.17-2.el7sat
  • M
Server-Side Request Forgery (SSRF)

<0:2.5.2.17-2.el7sat
  • M
Directory Traversal

<0:2.5.2.17-2.el7sat
  • M
Directory Traversal

<0:2.5.2.17-2.el7sat
  • H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<0:1.18.0.37-1.el7sat
  • H
Missing Authorization

<0:2.1.2.19-1.el7sat
  • H
Information Exposure

<0:1.18.0.37-1.el7sat
  • H
Improper Validation of Certificate with Host Mismatch

<0:2.1.2.19-1.el7sat
  • M
Execution with Unnecessary Privileges

<0:2.3.1.20-1.el7sat
  • M
Execution with Unnecessary Privileges

<0:2.3.1.20-1.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • H
HTTP Request Smuggling

<0:2.1.2.19-1.el7sat
  • M
Resource Exhaustion

<0:1.22.0.32-1.el7sat
  • M
Out-of-Bounds

<0:2.3.1.20-1.el7sat
  • M
Out-of-Bounds

<0:2.3.1.20-1.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:2.3.1.20-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:2.3.1.20-1.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • M
Resource Exhaustion

<0:2.5.2.17-2.el7sat
  • H
Cross-site Scripting (XSS)

<0:2.1.2.19-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:2.3.1.20-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:2.3.1.20-1.el7sat
  • H
Improper Input Validation

<0:2.1.2.19-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:2.3.1.20-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:2.3.1.20-1.el7sat
  • M
Improper Input Validation

<0:2.3.1.20-1.el7sat
  • M
Improper Input Validation

<0:2.3.1.20-1.el7sat
  • M
Improper Input Validation

<0:2.3.1.20-1.el7sat
  • M
Improper Input Validation

<0:2.3.1.20-1.el7sat
  • H
Eval Injection

<0:2.1.2.19-1.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • M
Information Exposure

<0:2.5.2.17-2.el7sat
  • M
OS Command Injection

<0:2.5.2.17-2.el7sat
  • M
OS Command Injection

<0:2.5.2.17-2.el7sat
  • M
XML External Entity (XXE) Injection

<0:2.5.2.17-2.el7sat
  • M
XML External Entity (XXE) Injection

<0:2.5.2.17-2.el7sat
  • H
Directory Traversal

<0:2.1.2.19-1.el7sat
  • H
HTTP Response Splitting

<0:2.1.2.19-1.el7sat
  • H
Incomplete Blacklist

<0:1.18.0.37-1.el7sat
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:2.1.2.19-1.el7sat
  • H
Integer Overflow or Wraparound

<0:1.15.6.34-1.el7sat
  • M
Improper Input Validation

<0:2.5.2.17-2.el7sat
  • M
Improper Input Validation

<0:2.5.2.17-2.el7sat
  • H
Improper Input Validation

<0:1.11.0.86-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • M
HTTP Response Splitting

<0:1.22.0.32-1.el7sat
  • H
CVE-2018-3258

<0:2.1.2.19-1.el7sat
  • M
Covert Timing Channel

<0:2.3.1.20-1.el7sat
  • H
Covert Timing Channel

<0:2.1.2.19-1.el7sat
  • M
Covert Timing Channel

<0:2.3.1.20-1.el7sat
  • M
Arbitrary Argument Injection

<0:1.22.0.32-1.el7sat
  • H
Out-of-Bounds

<0:1.18.0.37-1.el7sat
  • M
Improper Neutralization of Special Elements

<0:1.22.0.32-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.21-1.el7sat
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:2.5.2.17-2.el7sat
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:2.5.2.17-2.el7sat
  • M
CVE-2016-6346

<0:1.20.1.34-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • M
Incorrect Default Permissions

<0:2.5.2.17-2.el7sat
  • M
Incorrect Default Permissions

<0:2.5.2.17-2.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • M
Improper Neutralization of Special Elements

<0:1.22.0.32-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • M
Information Exposure

<0:2.3.1.20-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.39-2.el7sat
  • H
Deserialization of Untrusted Data

<0:2.1.2.19-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.24-1.el7sat
  • M
Use After Free

<0:2.3.1.20-1.el7sat
  • M
Use After Free

<0:2.3.1.20-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.24.1.21-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.22.0.36-1.el7sat