
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2016-20011 is a security vulnerability in libgrss, a GNOME RSS/Atom feed parsing library, related to TLS certificate verification. The issue was initially discovered and reported on October 9, 2016, where it was found that the library was using the deprecated SoupSessionSync class which did not perform TLS certificate verification by default (GNOME Bugzilla).
The vulnerability stems from the use of deprecated SoupSessionSync class in libgrss, which creates multiple instances (three SoupSessionSync and six SoupSessionAsync objects) without proper TLS certificate verification. The library did not utilize essential security properties such as ssl-ca-file, tls-database, or ssl-strict, resulting in no certificate verification being performed (GNOME Bugzilla).
The lack of TLS certificate verification could potentially allow attackers to perform man-in-the-middle attacks against applications using libgrss, as the library would not properly validate the authenticity of SSL/TLS certificates when establishing secure connections (GNOME Bugzilla).
Two solutions were proposed for this vulnerability: The ideal solution was to upgrade to modern SoupSession, which is secure by default. A simpler alternative was to set the ssl-use-system-ca-file property to TRUE for each SoupSession subclass, though this would need to be implemented in nine different places due to multiple session objects (GNOME Bugzilla).
The issue was eventually moved from GNOME's Bugzilla to their GitLab platform as part of GNOME's broader migration of their issue tracking system (GNOME Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."