CVE-2017-2667: Improper Certificate Validation
(updated )
Hammer CLI, a CLI utility for Foreman, does not explicitly set the verify_ssl
flag for apipie-bindings
. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
References
Detect and mitigate CVE-2017-2667 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →