Back to Database
Status published
High
CVE-2017-2667
Hammer CLI, a CLI utility for Foreman, before version 0.10.0,...
Vulnerability Description
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2667
Credits & Attribution
No credits recorded in the NVD database.
References
More from Foreman
View All →CVE-2017-7535
foreman before version 1.16.0 is vulnerable to a stored XSS...
Medium
6.1
CVE-2017-7505
Foreman since version 1.5 is vulnerable to an incorrect authorization...
High
8.8
CVE-2016-9595
A flaw was found in katello-debug before 3.4.0 where certain...
High
7.3
CVE-2016-7078
foreman before version 1.15.0 is vulnerable to an information leak...
Medium
4.3
CVE-2016-7077
foreman before 1.14.0 is vulnerable to an information leak. It...
Medium
4.3
Affected Vendor
Foreman
View all reports →Affected Software
Hammer CLI
Vulnerable Versions:
0.10.0
Timeline
Official Publish:
March 12th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H