Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17716

Опубликовано: 17 дек. 2017
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gitlab:gitlab:9.4.0:*:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:9.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:9.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:9.4.0:rc3:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:9.4.0:rc4:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:9.4.0:rc5:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:9.4.0:rc6:*:*:*:*:*:*
cpe:2.3:a:gitlab:gitlab:9.4.1:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00086
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.

CVSS3: 5.9
debian
больше 7 лет назад

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verifi ...

CVSS3: 5.9
github
около 3 лет назад

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.

EPSS

Процентиль: 26%
0.00086
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-295