CVE-2021-32066

Source
https://cve.org/CVERecord?id=CVE-2021-32066
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32066.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-32066
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLEANSTART (1)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (1)
openSUSE (9)
RHSA (9)
RLSA (3)
SUSE (4)
UBUNTU (1)
Related
Published
2021-08-01T19:15:07Z
Modified
2026-05-17T11:55:05Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "fixed":  "9.2.6.1"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "oracle:jd_edwards_enterpriseone_tools"
        }
    ]
}
References

Affected packages