Lucene search

K
osvGoogleOSV:CVE-2021-39361
HistoryAug 22, 2021 - 7:15 p.m.

CVE-2021-39361

2021-08-2219:15:07
Google
osv.dev
10
gnome
evolution-rss
network-soup
tls
certificate verification
soupsessionsync
mitm
cve-2021-39361

EPSS

0.003

Percentile

70.2%

In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.