Vulnerability Description
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/OfflineIMAP/offlineimap/issues/669
- https://github.com/OfflineIMAP/offlineimap3/commit/46505c53ef995455d66c685f9ec3f
- https://github.com/OfflineIMAP/offlineimap3/issues/222
- https://pypi.org/project/offlineimap/#history
- http://www.openwall.com/lists/oss-security/2026/06/08/3
FAQ
What is CVE-2020-37248?
CVE-2020-37248 is a vulnerability with a CVSS score of 6.5 (MEDIUM). OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account cr...
How severe is CVE-2020-37248?
CVE-2020-37248 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37248?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.