Vulnerability Name: | CVE-2021-39358 (CCN-208000) | ||||||||||||||||||||
Assigned: | 2021-05-25 | ||||||||||||||||||||
Published: | 2021-05-25 | ||||||||||||||||||||
Updated: | 2021-11-28 | ||||||||||||||||||||
Summary: | In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. Note: this is similar to CVE-2016-20011. | ||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
8.0 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:U/RC:R)
6.6 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-295 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-39358 Source: MISC Type: Vendor Advisory https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/ Source: XF Type: UNKNOWN gnome-cve202139358-mitm(208000) Source: CCN Type: libgfbgraph GIT Repository (CVE-2021-39358) Missing TLS certificate verification Source: MISC Type: Issue Tracking, Vendor Advisory https://gitlab.gnome.org/GNOME/libgfbgraph/-/issues/17 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-9c737bb848 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-7cccd2784c Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-743a0aafa0 Source: CCN Type: WhiteSource Vulnerability Database CVE-2021-3935 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |