CVE-2021-32066
Title: Stored Cross-Site Scripting and SSRF in myStickymenu WordPress plugin
XSS/SSRF
Proof Of Concept
No public PoC currently indexed for CVE-2021-32066.
CWE Category
CWE-755
Published Date
Aug 01, 2021
Modified Date
Nov 21, 2024
Exploit Status
Not Found
Score
7.4
CVSS v3.1
Exploit Probability (EPSS)
0.07%
Vulnerability Summary
CVE-2021-32066: An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
Impacted Vendors
Reference Links
https://github.com/ruby/ruby/commit/a21a3b7d23704a01d34bd79d09dc37897e00922a
https://hackerone.com/reports/1178562
https://lists.debian.org/debian-lts-announce/2021/10/msg00009.html
https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html
https://security.gentoo.org/glsa/202401-27
https://security.netapp.com/advisory/ntap-20210902-0004/
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.ruby-lang.org/en/news/2021/07/07/starttls-stripping-in-net-imap/
https://github.com/ruby/ruby/commit/a21a3b7d23704a01d34bd79d09dc37897e00922a
https://hackerone.com/reports/1178562
https://lists.debian.org/debian-lts-announce/2021/10/msg00009.html
https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html
https://security.gentoo.org/glsa/202401-27
https://security.netapp.com/advisory/ntap-20210902-0004/
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.ruby-lang.org/en/news/2021/07/07/starttls-stripping-in-net-imap/
CVSS v3.1
Source Entity
[email protected]
Severity
HIGH
7.4
Attack Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
5.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:P/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2021-32066 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Stack
No specific products linked.