{"id":"GHSA-4x25-f45x-grv5","summary":"Missing encryption in Apache Directory Studio","details":"While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.","aliases":["CVE-2021-33900"],"modified":"2023-11-08T04:06:06.534714Z","published":"2021-08-09T20:40:53Z","database_specific":{"nvd_published_at":"2021-07-26T07:15:00Z","cwe_ids":["CWE-311","CWE-319"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-08-02T21:23:12Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33900"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rb1dbcc43a5b406e45d335343a1704f4233de613140a01929d102fdc9%40%3Cusers.directory.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.directory.studio:org.apache.directory.studio.parent","ecosystem":"Maven","purl":"pkg:maven/org.apache.directory.studio/org.apache.directory.studio.parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.0.v20210717-M17"}]}],"versions":["2.0.0.v20150606-M9","2.0.0.v20151221-M10","2.0.0.v20161101-M12","2.0.0.v20170904-M13","2.0.0.v20180908-M14","2.0.0.v20200411-M15","2.0.0.v20210213-M16"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-4x25-f45x-grv5/GHSA-4x25-f45x-grv5.json","last_known_affected_version_range":"\u003c= 2.0.0.v20210213-M16"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}