Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77h8-xr85-3x5q

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

hammer_cli_foreman Improper Certificate Validation vulnerability

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

Пакеты

Наименование

hammer_cli_foreman

rubygems
Затронутые версииВерсия исправления

< 0.10.0

0.10.0

EPSS

Процентиль: 36%
0.00152
Низкий

8.1 High

CVSS3

Дефекты

CWE-295
CWE-345

Связанные уязвимости

CVSS3: 6.4
redhat
почти 9 лет назад

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

CVSS3: 8.1
nvd
почти 8 лет назад

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

CVSS3: 8.1
debian
почти 8 лет назад

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not ...

EPSS

Процентиль: 36%
0.00152
Низкий

8.1 High

CVSS3

Дефекты

CWE-295
CWE-345