CVE-2021-33900
26.07.2021, 07:15
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.Enginsight
Vendor | Product | Version |
---|---|---|
apache | directory_studio | 𝑥 ≤ 1.5.3 |
apache | directory_studio | 2.0.0:milestone1 |
apache | directory_studio | 2.0.0:milestone10 |
apache | directory_studio | 2.0.0:milestone11 |
apache | directory_studio | 2.0.0:milestone12 |
apache | directory_studio | 2.0.0:milestone13 |
apache | directory_studio | 2.0.0:milestone14 |
apache | directory_studio | 2.0.0:milestone15 |
apache | directory_studio | 2.0.0:milestone16 |
apache | directory_studio | 2.0.0:milestone2 |
apache | directory_studio | 2.0.0:milestone3 |
apache | directory_studio | 2.0.0:milestone4 |
apache | directory_studio | 2.0.0:milestone5 |
apache | directory_studio | 2.0.0:milestone6 |
apache | directory_studio | 2.0.0:milestone7 |
apache | directory_studio | 2.0.0:milestone8 |
apache | directory_studio | 2.0.0:milestone9 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.
- CWE-319 - Cleartext Transmission of Sensitive InformationThe software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.