CVE-2017-2667
published 2018-03-12CVE-2017-2667: Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a…
PriorityP434high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.73%
49.9th percentile
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foreman | hammer_cli | — | — |
| redhat | satellite | — | — |
| redhat | satellite_capsule | — | — |
| theforeman | hammer_cli | < 0.10.0 | 0.10.0 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
hammer_cli_foreman Improper Certificate Validation vulnerability
ghsa·2022-05-13
CVE-2017-2667 [HIGH] CWE-295 hammer_cli_foreman Improper Certificate Validation vulnerability
hammer_cli_foreman Improper Certificate Validation vulnerability
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
OSV
hammer_cli_foreman Improper Certificate Validation vulnerability
osv·2022-05-13
CVE-2017-2667 [HIGH] hammer_cli_foreman Improper Certificate Validation vulnerability
hammer_cli_foreman Improper Certificate Validation vulnerability
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Red Hat
rubygem-hammer_cli: no verification of API server's SSL certificate
vendor_redhat·2017-03-27·CVSS 8.1
CVE-2017-2667 [HIGH] CWE-345 rubygem-hammer_cli: no verification of API server's SSL certificate
rubygem-hammer_cli: no verification of API server's SSL certificate
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
It was found that the hammer_cli command line client disables SSL/TLS certificate verification by default. A man-in-the-middle (MITM) attacker could use this flaw to spoof a valid certificate.
Statement: This issue affects the versions of rubygem-hammer_cli as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer t
No detection rules found.
No public exploits indexed.
http://projects.theforeman.org/issues/19033http://www.securityfocus.com/bid/97153https://access.redhat.com/errata/RHSA-2018:0336https://bugzilla.redhat.com/show_bug.cgi?id=1436262http://projects.theforeman.org/issues/19033http://www.securityfocus.com/bid/97153https://access.redhat.com/errata/RHSA-2018:0336https://bugzilla.redhat.com/show_bug.cgi?id=1436262
2018-03-12
Published