{"api_version":"1","generated_at":"2026-07-23T05:41:54+00:00","cve":"CVE-2016-20011","urls":{"html":"https://cve.report/CVE-2016-20011","api":"https://cve.report/api/cve/CVE-2016-20011.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-20011","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-20011"},"summary":{"title":"CVE-2016-20011","description":"libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-05-25 21:15:00","updated_at":"2021-06-09 15:03:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://bugzilla.gnome.org/show_bug.cgi?id=772647","name":"https://bugzilla.gnome.org/show_bug.cgi?id=772647","refsource":"MISC","tags":[],"title":"Bug 772647 – Perform TLS certificate verification","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.gnome.org/GNOME/libgrss/-/issues/4","name":"https://gitlab.gnome.org/GNOME/libgrss/-/issues/4","refsource":"MISC","tags":[],"title":"(CVE-2016-20011) No TLS certificate verification (#4) · Issues · GNOME / libgrss · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch","name":"https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch","refsource":"MISC","tags":[],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-20011","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-20011","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"20011","vulnerable":"1","versionEndIncluding":"0.7.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"libgrss","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2016-20011","qid":"501604","title":"Alpine Linux Security Update for libgrss"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2016-20011","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://bugzilla.gnome.org/show_bug.cgi?id=772647","refsource":"MISC","name":"https://bugzilla.gnome.org/show_bug.cgi?id=772647"},{"url":"https://gitlab.gnome.org/GNOME/libgrss/-/issues/4","refsource":"MISC","name":"https://gitlab.gnome.org/GNOME/libgrss/-/issues/4"},{"refsource":"MISC","name":"https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch","url":"https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch"}]},"source":{"discovery":"INTERNAL"}},"nvd":{"publishedDate":"2021-05-25 21:15:00","lastModifiedDate":"2021-06-09 15:03:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gnome:libgrss:*:*:*:*:*:*:*:*","versionEndIncluding":"0.7.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"20011","Ordinal":"208974","Title":"CVE-2016-20011","CVE":"CVE-2016-20011","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"20011","Ordinal":"1","NoteData":"libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"20011","Ordinal":"2","NoteData":"2021-05-25","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"20011","Ordinal":"3","NoteData":"2021-06-08","Type":"Other","Title":"Modified"}]}}}