CVE-2017-11501 Information
Feb 14, 2021
cve
Description
NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to connect to the LDAP server with users.ldap.useTLS peer verification will be unconditionally disabled in /etc/ldap.conf.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Reference
http://openwall.com/lists/oss-security/2017/07/20/1 https://github.com/NixOS/nixpkgs/issues/27506 https://groups.google.com/forum/!topic/nix-security-announce/qrDU0KH_ZRk
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
5.9
Share on: