Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17718

Опубликовано: 14 янв. 2016
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.

Отчет

This issue affects the versions of rubygem-net-ldap as shipped with Red Hat Subscription Asset Manager 1 and Satellite version 6. Red Hat Product Security has rated this issue as having Moderate security impact. No update is planned at this time however a future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3ruby193-rubygem-net-ldapWill not fix
Red Hat Subscription Asset Managerruby193-rubygem-net-ldapWill not fix
Red Hat Satellite 6.7 for RHEL 7ansiblerole-foreman_scap_clientFixedRHSA-2020:145414.04.2020
Red Hat Satellite 6.7 for RHEL 7ansiblerole-insights-clientFixedRHSA-2020:145414.04.2020
Red Hat Satellite 6.7 for RHEL 7ansiblerole-satellite-receptor-installerFixedRHSA-2020:145414.04.2020
Red Hat Satellite 6.7 for RHEL 7ansible-runnerFixedRHSA-2020:145414.04.2020
Red Hat Satellite 6.7 for RHEL 7candlepinFixedRHSA-2020:145414.04.2020
Red Hat Satellite 6.7 for RHEL 7createrepo_cFixedRHSA-2020:145414.04.2020
Red Hat Satellite 6.7 for RHEL 7foremanFixedRHSA-2020:145414.04.2020
Red Hat Satellite 6.7 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2020:145414.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1527048rubygem-net-ldap: Missing SSL Certificate Validation

EPSS

Процентиль: 39%
0.00172
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 8 лет назад

The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.

CVSS3: 5.9
nvd
около 8 лет назад

The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.

CVSS3: 5.9
debian
около 8 лет назад

The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SS ...

CVSS3: 5.9
github
около 8 лет назад

net-ldap Improper Certificate Validation vulnerability

EPSS

Процентиль: 39%
0.00172
Низкий

4.8 Medium

CVSS3

Уязвимость CVE-2017-17718