CVE Vulnerabilities

CVE-2017-17716

Improper Certificate Validation

Published: Dec 17, 2017 | Modified: Jan 04, 2018
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 9.4.1 9.4.1
Gitlab Gitlab 9.4.0 9.4.0
Gitlab Gitlab 9.4.0 9.4.0
Gitlab Gitlab 9.4.0 9.4.0
Gitlab Gitlab 9.4.0 9.4.0
Gitlab Gitlab 9.4.0 9.4.0
Gitlab Gitlab 9.4.0 9.4.0
Gitlab Gitlab 9.4.0 9.4.0

Potential Mitigations

References