Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Startup TLS Trust Issue Enables Credential Disclosure |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext. | |
| First Time appeared |
Offlineimap
Offlineimap offlineimap |
|
| Weaknesses | CWE-348 | |
| CPEs | cpe:2.3:a:offlineimap:offlineimap:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Offlineimap
Offlineimap offlineimap |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-08T18:49:00.993Z
Reserved: 2026-06-08T15:05:08.771Z
Link: CVE-2020-37248
Updated: 2026-06-08T18:49:00.993Z
Status : Deferred
Published: 2026-06-08T16:16:33.257
Modified: 2026-06-09T13:57:49.980
Link: CVE-2020-37248
No data.
OpenCVE Enrichment
Updated: 2026-06-08T16:30:06Z