Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5152

Опубликовано: 17 июл. 2017
Источник: nvd
CVSS3: 8.1
CVSS2: 4.3
EPSS Низкий

Описание

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:theforeman:foreman:1.1-1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.3.0:rc4:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.6.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.3:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.4:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.7.5:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.8.0:rc3:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.8.3:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00291
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

redhat
больше 10 лет назад

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

CVSS3: 8.1
debian
больше 8 лет назад

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests ...

CVSS3: 8.1
github
больше 3 лет назад

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

EPSS

Процентиль: 52%
0.00291
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200