CVE-2020-13645
Last modified
CVE-2020-13645 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Balsa | < 2.5.11 |
| Gnome | Balsa | 2.6.0 |
| Gnome | Glib-Networking | < 2.62.4 |
| Gnome | Glib-Networking | >= 2.64.0, < 2.64.3 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.10 |
| Canonical | Ubuntu Linux | 20.04 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Netapp | Cloud Backup | All versions |
| Broadcom | Fabric Operating System | All versions |
References
- https://gitlab.gnome.org/GNOME/balsa/-/issues/34Exploit, Vendor Advisory
- https://gitlab.gnome.org/GNOME/glib-networking/-/issues/135Exploit, Vendor Advisory
- https://security.gentoo.org/glsa/202007-50Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200608-0004/Third Party Advisory
- https://usn.ubuntu.com/4405-1/Third Party Advisory
- https://gitlab.gnome.org/GNOME/balsa/-/issues/34Exploit, Vendor Advisory
- https://gitlab.gnome.org/GNOME/glib-networking/-/issues/135Exploit, Vendor Advisory
- https://security.gentoo.org/glsa/202007-50Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200608-0004/Third Party Advisory
- https://usn.ubuntu.com/4405-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-13645?
How severe is CVE-2020-13645?
How do I fix CVE-2020-13645?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-1364A denial of service vulnerability exists in the way that the…7.1
- CVE-2020-13640A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 …9.8
- CVE-2020-13641An issue was discovered in the Real-Time Find and Replace pl…8.8
- CVE-2020-13642An issue was discovered in the SiteOrigin Page Builder plugi…8.8
- CVE-2020-13643An issue was discovered in the SiteOrigin Page Builder plugi…8.8
- CVE-2020-13644An issue was discovered in the Accordion plugin before 2.2.9…5.4
- CVE-2020-13646In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) al…7.8
- CVE-2020-13649parser/js/js-scanner.c in JerryScript 2.2.0 mishandles error…7.5
- CVE-2020-1365An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-13650An issue was discovered in DigDash 2018R2 before p20200210 a…7.5
- CVE-2020-13651An issue was discovered in DigDash 2018R2 before p20200528, …7.8
- CVE-2020-13652An issue was discovered in DigDash 2018R2 before p20200528, …6.1
Are you affected by CVE-2020-13645?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
