Lucene search

K
cveMitreCVE-2017-17718
HistoryDec 17, 2017 - 9:29 p.m.

CVE-2017-17718

2017-12-1721:29:00
CWE-295
mitre
web.nvd.nist.gov
72
net::ldap
net-ldap
ruby
ssl certificate validation
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

48.7%

The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.

Affected configurations

Nvd
Node
net-ldap_projectnet-ldapMatch0.0.5ruby
OR
net-ldap_projectnet-ldapMatch0.1.0ruby
OR
net-ldap_projectnet-ldapMatch0.1.1ruby
OR
net-ldap_projectnet-ldapMatch0.2ruby
OR
net-ldap_projectnet-ldapMatch0.2.1ruby
OR
net-ldap_projectnet-ldapMatch0.2.2ruby
OR
net-ldap_projectnet-ldapMatch0.3.0ruby
OR
net-ldap_projectnet-ldapMatch0.3.1ruby
OR
net-ldap_projectnet-ldapMatch0.5.1ruby
OR
net-ldap_projectnet-ldapMatch0.6.0ruby
OR
net-ldap_projectnet-ldapMatch0.6.1ruby
OR
net-ldap_projectnet-ldapMatch0.7.0ruby
OR
net-ldap_projectnet-ldapMatch0.8.0ruby
OR
net-ldap_projectnet-ldapMatch0.9.0ruby
OR
net-ldap_projectnet-ldapMatch0.10.0ruby
OR
net-ldap_projectnet-ldapMatch0.10.1ruby
OR
net-ldap_projectnet-ldapMatch0.11ruby
OR
net-ldap_projectnet-ldapMatch0.12.0ruby
OR
net-ldap_projectnet-ldapMatch0.12.1ruby
OR
net-ldap_projectnet-ldapMatch0.13.0ruby
OR
net-ldap_projectnet-ldapMatch0.14.0ruby
OR
net-ldap_projectnet-ldapMatch0.15.0ruby
VendorProductVersionCPE
net-ldap_projectnet-ldap0.0.5cpe:2.3:a:net-ldap_project:net-ldap:0.0.5:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.1.0cpe:2.3:a:net-ldap_project:net-ldap:0.1.0:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.1.1cpe:2.3:a:net-ldap_project:net-ldap:0.1.1:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.2cpe:2.3:a:net-ldap_project:net-ldap:0.2:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.2.1cpe:2.3:a:net-ldap_project:net-ldap:0.2.1:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.2.2cpe:2.3:a:net-ldap_project:net-ldap:0.2.2:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.3.0cpe:2.3:a:net-ldap_project:net-ldap:0.3.0:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.3.1cpe:2.3:a:net-ldap_project:net-ldap:0.3.1:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.5.1cpe:2.3:a:net-ldap_project:net-ldap:0.5.1:*:*:*:*:ruby:*:*
net-ldap_projectnet-ldap0.6.0cpe:2.3:a:net-ldap_project:net-ldap:0.6.0:*:*:*:*:ruby:*:*
Rows per page:
1-10 of 221

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

48.7%