In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
{ "versions": [ { "introduced": "0" }, { "last_affected": "6.0.0" } ] }
[ { "events": [ { "introduced": "0" }, { "last_affected": "34" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "35" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39359.json"