CVE-2020-37248
EUVD-2020-3125008.06.2026, 16:16
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| offlineimap | offlineimap | 𝑥 < 8.0.3 | CNA |
Debian Releases
Common Weakness Enumeration
References