libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgrss | Oct 1, 2024 | May 25, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 25, 2021 |
| Debian | — | No solution exists | May 15, 2025 | May 25, 2021 |
| Oracle Solaris | — | Upgrade library/desktop/grilo-plugins to version 0.3.12-11.4.38.0.1.101.3 on Solaris 11.4Upgrade library/desktop/grilo to version 0.3.13-11.4.38.0.1.101.3 on Solaris 11.4 | Nov 17, 2021 | May 25, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub