Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2667

Опубликовано: 12 мар. 2018
Источник: debian

Описание

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
foremanitppackage

Связанные уязвимости

CVSS3: 6.4
redhat
почти 9 лет назад

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

CVSS3: 8.1
nvd
почти 8 лет назад

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

CVSS3: 8.1
github
больше 3 лет назад

hammer_cli_foreman Improper Certificate Validation vulnerability