CVE-2016-20011 affects libgrss through version 0.7.0, a GNOME library, by failing to perform TLS certificate verification when downloading RSS feeds. This vulnerability, rated HIGH (CVSS 7.5), allows remote attackers to intercept and manipulate feed content without detection due to the default behavior of SoupSessionSync. While the attack complexity is low and requires no user interaction, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.7.0CPE matchmatch criteria | cpe:2.3:a:gnome:libgrss:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.