Theforeman

Hammer Cli

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 13.12.2019 13:15:11
  • Last modified 21.11.2024 02:01:44

rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

  • EPSS 0.11%
  • Published 12.03.2018 15:29:00
  • Last modified 21.11.2024 03:23:56

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middl...