RubySec

Providing security resources for the Ruby community

CVE-2017-17718 (net-ldap): No validation of hostname certificate in net-ldap

No validation of hostname certificate in net-ldap

Published: December 17, 2017

SECURITY IDENTIFIERS

GEM

net-ldap

SEVERITY

CVSS v3.x: 5.9 (Medium)

PATCHED VERSIONS

>= 0.16.0

DESCRIPTION

The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation. The LDAP server's certificate was not verified to match the host it was supposed to be connecting to.

RELATED