5.9
CVSSv3

CVE-2021-39360

Published: 22/08/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In GNOME libzapojit up to and including 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome libzapojit

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Debian Bug report logs - #993538 libzapojit: CVE-2021-39360 Package: src:libzapojit; Maintainer for src:libzapojit is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 2 Sep 2021 20:09:01 UTC Severity: important Tags: security, ...
In GNOME libzapojit through 003, zpj-skydrivec does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks NOTE: this is similar to CVE-2016-20011 (CVE-2021-39360) ...
In GNOME libzapojit through 003, zpj-skydrivec does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks NOTE: this is similar to CVE-2016-20011 ...
In GNOME libzapojit through 003, zpj-skydrivec does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks NOTE: this is similar to CVE-2016-20011 ...