An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-05-29T00:00:00
Updated: 2024-08-04T16:55:10.308Z
Reserved: 2020-12-04T00:00:00
Link: CVE-2020-29547
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-29T19:15:09.413
Modified: 2024-11-21T05:24:10.637
Link: CVE-2020-29547
Redhat
No data.