CVE-2021-32066

    Dashboard / Vulnerabilities / CVE-2021-32066

    CVE-2021-32066

    Published: 1 Aug 2021Last Modified: 8 Jul 2026

    Summary:

    Details: An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- c1af7b1e1d408f9796a5f46c9ed36bc5adea4aa2
    Fixed -None

    Affected versions

    v3_0_1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2021-32066 | CVE-DB