Security Flaw in Hammer CLI Utility Affecting Foreman by Red Hat
CVE-2017-2667
8.1HIGH
What is CVE-2017-2667?
The Hammer CLI utility for Foreman, prior to version 0.10.0, contains a security flaw where it fails to explicitly set the verify_ssl flag for apipie-bindings. This oversight results in server certificates not being checked, leaving connections vulnerable to man-in-the-middle attacks. Attackers can exploit this lack of certificate verification to intercept and manipulate communications between the client and the server, posing serious security risks to users and their data.
Affected Version(s)
Hammer CLI 0.10.0
