7.5

CVE-2021-33900

While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheDirectory Studio Version <= 1.5.3
ApacheDirectory Studio Version2.0.0 Updatemilestone1
ApacheDirectory Studio Version2.0.0 Updatemilestone10
ApacheDirectory Studio Version2.0.0 Updatemilestone11
ApacheDirectory Studio Version2.0.0 Updatemilestone12
ApacheDirectory Studio Version2.0.0 Updatemilestone13
ApacheDirectory Studio Version2.0.0 Updatemilestone14
ApacheDirectory Studio Version2.0.0 Updatemilestone15
ApacheDirectory Studio Version2.0.0 Updatemilestone16
ApacheDirectory Studio Version2.0.0 Updatemilestone2
ApacheDirectory Studio Version2.0.0 Updatemilestone3
ApacheDirectory Studio Version2.0.0 Updatemilestone4
ApacheDirectory Studio Version2.0.0 Updatemilestone5
ApacheDirectory Studio Version2.0.0 Updatemilestone6
ApacheDirectory Studio Version2.0.0 Updatemilestone7
ApacheDirectory Studio Version2.0.0 Updatemilestone8
ApacheDirectory Studio Version2.0.0 Updatemilestone9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.349
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.