First published: Mon Mar 27 2017(Updated: )
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Theforeman Hammer Cli | <0.10.0 | |
Redhat Satellite | =6.3 | |
Redhat Satellite Capsule | =6.3 | |
rubygems/hammer_cli_foreman | <0.10.0 | 0.10.0 |
<0.10.0 | ||
=6.3 | ||
=6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.