libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-05-25T20:09:43
Updated: 2024-08-06T03:47:35.031Z
Reserved: 2021-05-25T00:00:00
Link: CVE-2016-20011
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-05-25T21:15:07.290
Modified: 2024-11-21T02:47:33.073
Link: CVE-2016-20011
Redhat
No data.