CVE-2021-39360
published 2021-08-22CVE-2021-39360: In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users…
PriorityP427medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.83%
53.5th percentile
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libzapojit | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnome | libzapojit | <= 0.0.3 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3j9h-5r8r-rrxc: In GNOME libzapojit through 0
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2021-39360 [HIGH] CWE-295 GHSA-3j9h-5r8r-rrxc: In GNOME libzapojit through 0
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
OSV
CVE-2021-39360: In GNOME libzapojit through 0
osv·2021-08-22·CVSS 7.5
CVE-2021-39360 [HIGH] CVE-2021-39360: In GNOME libzapojit through 0
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Red Hat
libzapojit: missing TLS certificate verification
vendor_redhat·2021-08-22·CVSS 7.5
CVE-2021-39360 [HIGH] CWE-295 libzapojit: missing TLS certificate verification
libzapojit: missing TLS certificate verification
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Package: libzapojit (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2021-39360: libzapojit - In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificat...
vendor_debian·2021·CVSS 7.5
CVE-2021-39360 [HIGH] CVE-2021-39360: libzapojit - In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificat...
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Scope: local
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/https://gitlab.gnome.org/GNOME/libzapojit/-/issues/4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDXCHOCVP3VSAKDBQSLER2DQHFIOUHAT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNSIMQXP6VQWJXI7VW7ZCLCS4NWW465T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UG7TUICJM4QJHI4QJ2RHOSQE2QWD3KO3/https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/https://gitlab.gnome.org/GNOME/libzapojit/-/issues/4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDXCHOCVP3VSAKDBQSLER2DQHFIOUHAT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNSIMQXP6VQWJXI7VW7ZCLCS4NWW465T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UG7TUICJM4QJHI4QJ2RHOSQE2QWD3KO3/
2021-08-22
Published