AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-5152

HIGH · CVSS 8.1 EPSS 1.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-07-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2015-5152
Severity
HIGH
CVSS
8.1
EPSS
1.51%

Original NVD Description

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.

Related CVEs

Other vulnerabilities affecting the same vendor(s)