hammer_cli_foreman Improper Certificate Validation vulnerability
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 26, 2024
Description
Published by the National Vulnerability Database
Mar 12, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 27, 2023
Last updated
Jan 26, 2024
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
References