Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2017-17718
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2017-17718
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17718.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-17718
Aliases
GHSA-m7p8-9w66-9frm
Downstream
DEBIAN-CVE-2017-17718
RHSA-2020:1454
UBUNTU-CVE-2017-17718
Published
2017-12-17T21:29:00Z
Modified
2025-09-19T08:57:34.852224Z
Severity
5.9 (Medium)
CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
[none]
Details
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
References
http://openwall.com/lists/oss-security/2017/12/17/10
https://github.com/ruby-ldap/ruby-net-ldap/issues/258
https://github.com/ruby-ldap/ruby-net-ldap/pull/279
Affected packages
Git
/
github.com/ruby-ldap/ruby-net-ldap
Affected ranges
Type
GIT
Repo
https://github.com/ruby-ldap/ruby-net-ldap
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
02804d7c18050d7397beaa7c43d65b56bbf30521
Last affected
028cdeebbd5ff8262ddcaa12811253536a6edcd3
Last affected
2f053dd12264da42d90144341b4c0f0d8a372349
Last affected
3bf849d415a691b5632f2e20cc637e377b15b2ad
Last affected
449370b5cfeae01a1d9a425fa0e649462ae83840
Last affected
51a7ea4f23432b808dec207d106173ba8d124233
Last affected
67d8311aed6de49f4f2007e67b5e01ac7787c88e
Last affected
77387bfc6a27b1b3b854942d16c09f5c568509ee
Last affected
85e4b92c809fa96f3efb06b5b87c004f5390cc18
Last affected
9f29e158d310dc1c9a7084a87b7d57d4aa47683c
Last affected
a046753c9fdd622be3bdd25ed244eb7cc7f1543c
Last affected
c326a4d7623974402979a3aa5ea13299bf4c4590
Last affected
d4a73558ef847d6e0e19f5697f3e1003d1758d15
Last affected
d6ad919717a05b98b1c2f32f7292fe19381a9a82
Last affected
e37ce91b6e4422bce3fd1092119ebe42a3c986ec
Last affected
f765a75fd07f37363a4c9b80f5bb828956746f5f
Last affected
fd2d1ed62df1e65a50627b429bce7a49cd623b04
Affected versions
v0.*
v0.2
v0.2.1
v0.2.2
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.7.0
CVE-2017-17718 - OSV