Vulnerability Details CVE-2017-2667
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.7%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2017-2667
-
cpe:2.3:a:redhat:satellite:6.3
-
cpe:2.3:a:redhat:satellite_capsule:6.3
-
cpe:2.3:a:theforeman:hammer_cli:-
-
cpe:2.3:a:theforeman:hammer_cli:0.0.10
-
cpe:2.3:a:theforeman:hammer_cli:0.0.11
-
cpe:2.3:a:theforeman:hammer_cli:0.0.12
-
cpe:2.3:a:theforeman:hammer_cli:0.0.13
-
cpe:2.3:a:theforeman:hammer_cli:0.0.14
-
cpe:2.3:a:theforeman:hammer_cli:0.0.15
-
cpe:2.3:a:theforeman:hammer_cli:0.0.16
-
cpe:2.3:a:theforeman:hammer_cli:0.0.17
-
cpe:2.3:a:theforeman:hammer_cli:0.0.18
-
cpe:2.3:a:theforeman:hammer_cli:0.0.2
-
cpe:2.3:a:theforeman:hammer_cli:0.0.3
-
cpe:2.3:a:theforeman:hammer_cli:0.0.5
-
cpe:2.3:a:theforeman:hammer_cli:0.0.6
-
cpe:2.3:a:theforeman:hammer_cli:0.0.7
-
cpe:2.3:a:theforeman:hammer_cli:0.0.8
-
cpe:2.3:a:theforeman:hammer_cli:0.0.9
-
cpe:2.3:a:theforeman:hammer_cli:0.1.0
-
cpe:2.3:a:theforeman:hammer_cli:0.1.1
-
cpe:2.3:a:theforeman:hammer_cli:0.1.2
-
cpe:2.3:a:theforeman:hammer_cli:0.1.3
-
cpe:2.3:a:theforeman:hammer_cli:0.1.4
-
cpe:2.3:a:theforeman:hammer_cli:0.2.0
-
cpe:2.3:a:theforeman:hammer_cli:0.3.0
-
cpe:2.3:a:theforeman:hammer_cli:0.4.0
-
cpe:2.3:a:theforeman:hammer_cli:0.5.0
-
cpe:2.3:a:theforeman:hammer_cli:0.5.1
-
cpe:2.3:a:theforeman:hammer_cli:0.6.0
-
cpe:2.3:a:theforeman:hammer_cli:0.6.1
-
cpe:2.3:a:theforeman:hammer_cli:0.6.2
-
cpe:2.3:a:theforeman:hammer_cli:0.7.0
-
cpe:2.3:a:theforeman:hammer_cli:0.8.0
-
cpe:2.3:a:theforeman:hammer_cli:0.9.0