CVE-2021-39359
published 2021-08-22CVE-2021-39359: In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users…
PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.10%
62.0th percentile
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libgda5 | < libgda5 5.2.10-5 (forky) | libgda5 5.2.10-5 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnome | libgda | <= 6.0.0 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p8hp-p5rw-j34r: In GNOME libgda through 6
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2021-39359 [HIGH] CWE-295 GHSA-p8hp-p5rw-j34r: In GNOME libgda through 6
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
OSV
CVE-2021-39359: In GNOME libgda through 6
osv·2021-08-22·CVSS 7.5
CVE-2021-39359 [HIGH] CVE-2021-39359: In GNOME libgda through 6
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Debian
CVE-2021-39359: libgda5 - In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificat...
vendor_debian·2021·CVSS 7.5
CVE-2021-39359 [HIGH] CVE-2021-39359: libgda5 - In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificat...
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.2.10-5)
sid: resolved (fixed in 5.2.10-5)
trixie: resolved (fixed in 5.2.10-5)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/https://github.com/GNOME/libgda/commit/bd7b9568bcd9f6d3e6680bb04323a670c842a62dhttps://gitlab.gnome.org/GNOME/libgda/-/issues/249https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRPPP47WRCAPAEJGRMEKYYJZBQCYXTLQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLMVVIJNY5NMOT3FH36RFBWOTPVW7GME/https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/https://github.com/GNOME/libgda/commit/bd7b9568bcd9f6d3e6680bb04323a670c842a62dhttps://gitlab.gnome.org/GNOME/libgda/-/issues/249https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRPPP47WRCAPAEJGRMEKYYJZBQCYXTLQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLMVVIJNY5NMOT3FH36RFBWOTPVW7GME/
2021-08-22
Published