Логотип exploitDog
bind:CVE-2015-5152
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-5152

Количество 4

Количество 4

redhat логотип

CVE-2015-5152

больше 10 лет назад

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5152

больше 8 лет назад

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2015-5152

больше 8 лет назад

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-f78j-3cq3-m6p4

больше 3 лет назад

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2015-5152

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-5152

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

CVSS3: 8.1
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2015-5152

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests ...

CVSS3: 8.1
0%
Низкий
больше 8 лет назад
github логотип
GHSA-f78j-3cq3-m6p4

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу