SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-11501

NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP.

MEDIUM 5.9EPSS 0.88%

Does this matter?

Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.

Description

NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to connect to the LDAP server with users.ldap.useTLS, peer verification will be unconditionally disabled in /etc/ldap.conf.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.88% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
nixos project/nixos
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.