DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
| Software | From | Fixed in |
|---|---|---|
| ldaptive / ldaptive | - | 1.0.5 |
| ldaptive / vt-ldap | - | 3.3.8 |
edu.vt.middleware / vt-ldap
|
- | 3.3.8 |
edu.internet2.middleware / shibboleth-identityprovider
|
- | 2.4.2 |