CVE-2021-32066

Advisory lineage Upstream: 0 Downstream: 30
Modified
Published: 01 Aug 2021, 00:00
Last modified:03 Aug 2024, 23:17

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.4 HIGH
v3.1 (nvd)
EPSS Score
0.07% LOW
0% probability -0.04%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

01 Aug 2021, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 23:17
Last Modified
Vulnerability information updated

Description

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.07% Percentile: 22%

Techniques & Countermeasures

  • CWE-755Improper Handling of Exceptional Conditions

    The product does not handle or incorrectly handles an exceptional condition.

Affected Systems

  • oraclejd_edwards_enterpriseone_tools

    < 9.2.6.1

  • ruby-langruby

    ≥ 2.6.0, ≤ 2.6.7 | ≥ 2.7.0, ≤ 2.7.3 | ≥ 3.0.0, ≤ 3.0.1

References (8)