CVE-2017-2667

Impact:
Moderate
Public Date:
2017-03-27
CWE:
CWE-345
Bugzilla:
1436262: CVE-2017-2667 rubygem-hammer_cli: no verification of API server's SSL certificate
It was found that the hammer_cli command line client disables SSL/TLS certificate verification by default. A man-in-the-middle (MITM) attacker could use this flaw to spoof a valid certificate.

Find out more about CVE-2017-2667 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue affects the versions of rubygem-hammer_cli as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

CVSS v3 metrics

CVSS3 Base Score 6.4
CVSS3 Base Metrics CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Vector Adjacent Network
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Satellite 6.3 RHSA-2018:0336 2018-02-21
Red Hat Satellite Capsule 6.3 RHSA-2018:0336 2018-02-21

Affected Packages State

Platform Package State
Red Hat Satellite 6 rubygem-hammer_cli Will not fix
Red Hat Enterprise Linux 7 rubygem-hammer_cli Will not fix
Red Hat Enterprise Linux 6 rubygem-hammer_cli Will not fix
OpenStack 6 Installer for RHEL 7 rubygem-hammer_cli Will not fix

Acknowledgements

This issue was discovered by Tomas Strachota (Red Hat).

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.