cbcvebase.
CVE-2021-38165
published 2021-08-07

CVE-2021-38165: Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in…

PriorityP434medium5.3CVSS 3.1
AVNACHPRNUIRSUCHINAN
EPSS
4.07%
89.7th percentile
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlynx< lynx 2.9.0dev.6-3 (bookworm)lynx 2.9.0dev.6-3 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
lynx_projectlynx<= 2.8.9
lynx_projectlynx>= 0 < 2.9.0dev.6-3~deb11u12.9.0dev.6-3~deb11u1
lynx_projectlynx>= 0 < 2.9.0dev.6-32.9.0dev.6-3
lynx_projectlynx>= 0 < 2.9.0dev.6-32.9.0dev.6-3
lynx_projectlynx>= 0 < 2.9.0dev.6-32.9.0dev.6-3

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.