Vulnerability Name: | CVE-2021-39360 (CCN-208003) | ||||||||||||||||
Assigned: | 2021-05-25 | ||||||||||||||||
Published: | 2021-05-25 | ||||||||||||||||
Updated: | 2021-11-28 | ||||||||||||||||
Summary: | In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. Note: this is similar to CVE-2016-20011. | ||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
8.0 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-295 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-39360 Source: MISC Type: Vendor Advisory https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/ Source: XF Type: UNKNOWN gnome-cve202139360-mitm(208003) Source: CCN Type: libzapojit GIT Repository (CVE-2021-39360) Missing TLS certificate verification Source: MISC Type: Issue Tracking, Vendor Advisory https://gitlab.gnome.org/GNOME/libzapojit/-/issues/4 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-c3395a5df6 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-7f5a82ef57 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-77ce69dba6 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |