CVE-2012-5477: Theforeman Foreman
Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
Affected products
- Theforeman Foreman: up to and including 1.0
Published 2014-05-08. Last modified 2026-06-16.