Hammer CLI
by Theforeman
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-2667 | Hig | 0.53 | 8.1 | 0.01 | Mar 12, 2018 | Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks. | ||
| CVE-2014-0241 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2019 | rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable |
- risk 0.53cvss 8.1epss 0.01
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
- risk 0.36cvss 5.5epss 0.00
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable