CVE-2014-0083 rubygem-net-ldap: SSHA passwords generated by the net-ldap Ruby gem use a weak salt
Published: February 13, 2014
SECURITY IDENTIFIERS
- CVE: CVE-2014-0083 (NVD)
- GHSA: GHSA-qwgm-mxm4-3q2c
- OSVDB: OSVDB-106108
GEM
SEVERITY
PATCHED VERSIONS
>= 0.6.0
DESCRIPTION
The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
