OfflineIMAP
cpe:2.3:a:offlineimap:offlineimap:*:*:*:*:*:*:*
- < 8.0.3
A vulnerability exists in OfflineIMAP versions prior to 8.0.3, where the application fails to properly enforce STARTTLS when the server does not explicitly advertise its availability. This oversight can lead to STRIPTLS attacks, allowing a man-in-the-middle to intercept the connection and capture account credentials in cleartext. The issue arises because OfflineIMAP relies on the server's capability list instead of enforcing user-configured security settings.
Exploitation of this vulnerability allows for interception of credentials in cleartext, creating a risk of unauthorized account access.
To reproduce this vulnerability, configure OfflineIMAP to use STARTTLS and connect to a server that does not advertise STARTTLS support. The application will skip the encryption, leaving the connection unprotected and allowing credentials to be sent in plaintext.
Users can upgrade to OfflineIMAP version 8.0.3 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.