CVE-2021-39360: Medium severity Gnome libzapojit vulnerability
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39360?
CVE-2021-39360 is a vulnerability in GNOME libzapojit through 0.0.3 that does not enable TLS certificate verification, making users vulnerable to network MITM attacks.
How does CVE-2021-39360 affect GNOME libzapojit?
CVE-2021-39360 affects GNOME libzapojit through version 0.0.3 by not enabling TLS certificate verification on SoupSessionSync objects.
What is the severity of CVE-2021-39360?
The severity of CVE-2021-39360 is medium, with a severity value of 5.9.
Which software versions are affected by CVE-2021-39360?
GNOME libzapojit version 0.0.3, Fedora 33, Fedora 34, and Fedora 35 are affected by CVE-2021-39360.
How can I fix CVE-2021-39360?
To fix CVE-2021-39360, it is recommended to update to the latest version of GNOME libzapojit or apply any patches provided by the software vendor.