VulnerabilityModified
CVE-2017-11501
NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP.
MEDIUM 5.9EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to connect to the LDAP server with users.ldap.useTLS, peer verification will be unconditionally disabled in /etc/ldap.conf.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- nixos project/nixos
- Source
- cve@mitre.org
References
- http://openwall.com/lists/oss-security/2017/07/20/1Mailing List, Mitigation, Patch, Third Party Advisory
- https://github.com/NixOS/nixpkgs/issues/27506Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21topic/nix-security-announce/qrDU0KH_ZRk
- http://openwall.com/lists/oss-security/2017/07/20/1Mailing List, Mitigation, Patch, Third Party Advisory
- https://github.com/NixOS/nixpkgs/issues/27506Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21topic/nix-security-announce/qrDU0KH_ZRk
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.