Security Flaw in Hammer CLI Utility Affecting Foreman by Red Hat
CVE-2017-2667
8.1HIGH
What is CVE-2017-2667?
The Hammer CLI utility for Foreman, prior to version 0.10.0, contains a security flaw where it fails to explicitly set the verify_ssl flag for apipie-bindings. This oversight results in server certificates not being checked, leaving connections vulnerable to man-in-the-middle attacks. Attackers can exploit this lack of certificate verification to intercept and manipulate communications between the client and the server, posing serious security risks to users and their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Hammer CLI 0.10.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
