OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 08 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Startup TLS Trust Issue Enables Credential Disclosure |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext. | |
| First Time appeared |
Offlineimap
Offlineimap offlineimap |
|
| Weaknesses | CWE-348 | |
| CPEs | cpe:2.3:a:offlineimap:offlineimap:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Offlineimap
Offlineimap offlineimap |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-08T15:06:07.728Z
Reserved: 2026-06-08T15:05:08.771Z
Link: CVE-2020-37248
No data.
Status : Received
Published: 2026-06-08T16:16:33.257
Modified: 2026-06-08T16:16:33.257
Link: CVE-2020-37248
No data.
OpenCVE Enrichment
Updated: 2026-06-08T16:30:06Z
Weaknesses