CVE-2017-2623 | rpm-ostree/rpm-ostree-client prior 2017.3 GPG Signature certificate validation (FEDORA-2017-788129b61c / Nessus ID 97867)
A vulnerability, which was classified as critical, has been found in rpm-ostree and rpm-ostree-client. Affected by this issue is some unknown functionality of the component GPG Signature Handler. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2017-2623. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.