CVE-2012-5477: Theforeman Foreman

Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.

The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.

Affected products

Published 2014-05-08. Last modified 2026-06-16.