PT-2026-47305 · Offlineimap+3 · Offlineimap+1
CVE-2020-37248
·
Published
2026-06-08
·
Updated
2026-06-08
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OfflineIMAP versions prior to 8.0.3
Description
The software trusts the server with its STARTTLS capability before authentication occurs. This allows for STRIPTLS and man-in-the-middle attacks, where an attacker can take over the connection and extract account credentials in cleartext.
Recommendations
Update to version 8.0.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Offlineimap
Offlineimap3