CVE-2017-11501
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to connect to the LDAP server with users.ldap.useTLS, peer verification will be unconditionally disabled in /etc/ldap.conf.
NixOS versión 17.03 y anteriores tienen una ausencia predeterminada involuntaria de la comprobación de certificado SSL para LDAP. El módulo users.ldap NixOS implementa la identificación de usuarios contra servidores LDAP por medio de un módulo PAM. Se encontró que si TLS está habilitado para conectarse al servidor LDAP con users.ldap.useTLS, la verificación entre iguales se deshabilitará incondicionalmente en /etc/ldap.conf.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-20 CVE Reserved
- 2017-07-20 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/NixOS/nixpkgs/issues/27506 | Issue Tracking | |
https://groups.google.com/forum/#%21topic/nix-security-announce/qrDU0KH_ZRk | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://openwall.com/lists/oss-security/2017/07/20/1 | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nixos Project Search vendor "Nixos Project" | Nixos Search vendor "Nixos Project" for product "Nixos" | <= 17.03 Search vendor "Nixos Project" for product "Nixos" and version " <= 17.03" | - |
Affected
|