GHSA-77h8-xr85-3x5q

    Dashboard / Vulnerabilities / GHSA-77h8-xr85-3x5q

    GHSA-77h8-xr85-3x5q

    Published: 13 May 2022Last Modified: 16 Feb 2024
    Aliases:

    Summary: hammer_cli_foreman Improper Certificate Validation vulnerability

    Details: Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

    Affected packages

    Package

    Name: hammer_cli_foreman

    Purl: pkg:gem/hammer_cli_foreman

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.10.0

    Affected versions

    0.0.10
    0.0.11
    0.0.12
    0.0.13
    0.0.14
    0.0.15
    0.0.16
    0.0.17
    0.0.18
    0.0.4
    0.0.5
    0.0.6
    0.0.7
    0.0.8
    0.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-77h8-xr85-3x5q | CVE-DB