foreman-mcp-server@0.3.1

MCP server for Foreman host management and infrastructure automation

Direct Vulnerabilities

Known vulnerabilities in the foreman-mcp-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Insertion of Sensitive Information into Log File

foreman-mcp-server is a MCP server for Foreman host management and infrastructure automation

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the _sanitize_headers method in logging.py, which used a denylist approach to redact sensitive HTTP headers before logging. Because only a fixed set of known header names (foreman_password, foreman_token, password, token) were masked, any other header carrying credentials or tokens - such as authorization or custom authentication headers - was logged in plaintext. An attacker with read access to the application logs can recover those credential values.

How to fix Insertion of Sensitive Information into Log File?

A fix was pushed into the master branch but not yet published.

[0,)