← Back

CVE-2021-33900

nvd nist
Published: Jul 26, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.

Affected (17)

1 product
Directory Studio
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Up to 1.5.3
Version 2.0.0 milestone10
Version 2.0.0 milestone11
Version 2.0.0 milestone12
Version 2.0.0 milestone13
Version 2.0.0 milestone14
Version 2.0.0 milestone15
Version 2.0.0 milestone16
Version 2.0.0 milestone1
Version 2.0.0 milestone2
Version 2.0.0 milestone3
Version 2.0.0 milestone4
Version 2.0.0 milestone5
Version 2.0.0 milestone6
Version 2.0.0 milestone7
Version 2.0.0 milestone8
Version 2.0.0 milestone9

Timeline

No history available yet.