CVE-2021-33900
StartTLS and SASL confidentiality protection bypass
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
26 jul 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
Productos afectados
Apache Software Foundation · Apache Directory Studio¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →