CVE Vulnerabilities

CVE-2020-15954

Cleartext Transmission of Sensitive Information

Published: Jul 27, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Kmail Kde 19.12.3 (including) 19.12.3 (including)
Kdepim-runtime Ubuntu bionic *
Kdepim-runtime Ubuntu focal *
Kdepim-runtime Ubuntu groovy *
Kdepim-runtime Ubuntu hirsute *
Kdepim-runtime Ubuntu impish *
Kdepim-runtime Ubuntu kinetic *
Kdepim-runtime Ubuntu lunar *
Kdepim-runtime Ubuntu mantic *
Kdepim-runtime Ubuntu oracular *
Kdepim-runtime Ubuntu trusty *
Kdepim-runtime Ubuntu xenial *
Kmail-account-wizard Ubuntu bionic *
Kmail-account-wizard Ubuntu focal *
Kmail-account-wizard Ubuntu groovy *
Kmail-account-wizard Ubuntu hirsute *
Kmail-account-wizard Ubuntu impish *
Kmail-account-wizard Ubuntu kinetic *
Kmail-account-wizard Ubuntu lunar *
Kmail-account-wizard Ubuntu mantic *
Kmail-account-wizard Ubuntu oracular *
Kmail-account-wizard Ubuntu trusty *

Potential Mitigations

References