Vulnerability Details CVE-2021-33900
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-33900
-
cpe:2.3:a:apache:directory_studio:0.6.0
-
cpe:2.3:a:apache:directory_studio:0.7.0
-
cpe:2.3:a:apache:directory_studio:0.8.0
-
cpe:2.3:a:apache:directory_studio:0.8.1
-
cpe:2.3:a:apache:directory_studio:0.8.2
-
cpe:2.3:a:apache:directory_studio:1.0.0
-
cpe:2.3:a:apache:directory_studio:1.0.1
-
cpe:2.3:a:apache:directory_studio:1.1.0
-
cpe:2.3:a:apache:directory_studio:1.2.0
-
cpe:2.3:a:apache:directory_studio:1.3.0
-
cpe:2.3:a:apache:directory_studio:1.4.0
-
cpe:2.3:a:apache:directory_studio:1.5.0
-
cpe:2.3:a:apache:directory_studio:1.5.1
-
cpe:2.3:a:apache:directory_studio:1.5.2
-
cpe:2.3:a:apache:directory_studio:1.5.3
-
cpe:2.3:a:apache:directory_studio:2.0.0