CVE-2015-5152: Theforeman Foreman
High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
Affected products
- Theforeman Foreman: version 1.1-1 only; version 1.2.0 only; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only; version 1.3.0 only; …
Published 2017-07-17. Last modified 2026-06-17.