CVE-2016-20011

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
25/05/2021
Last modified:
09/06/2021

Description

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnome:libgrss:*:*:*:*:*:*:*:* 0.7.0 (including)