CVE-2019-3890
published 2019-08-01CVE-2019-3890: It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential…
PriorityP336high8.1CVSS 3.0
AVNACLPRNUIRSUCHIHAN
EPSS
0.99%
58.9th percentile
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution-ews | < evolution-ews 3.30.5-1.1 (bookworm) | evolution-ews 3.30.5-1.1 (bookworm) |
| gnome | evolution-ews | < 3.31.3 | 3.31.3 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| the_gnome_project | evolution-ews | — | — |
| the_gnome_project | evolution-ews | >= 0 < 3.30.5-1.1 | 3.30.5-1.1 |
| the_gnome_project | evolution-ews | >= 0 < 3.30.5-1.1 | 3.30.5-1.1 |
| the_gnome_project | evolution-ews | >= 0 < 3.30.5-1.1 | 3.30.5-1.1 |
| the_gnome_project | evolution-ews | >= 0 < 3.30.5-1.1 | 3.30.5-1.1 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
evolution-ews: all certificate errors ignored if error is ignored during initial account setup in gnome-online-accounts
vendor_redhat·2019-02-15·CVSS 8.1
CVE-2019-3890 [HIGH] CWE-295 evolution-ews: all certificate errors ignored if error is ignored during initial account setup in gnome-online-accounts
evolution-ews: all certificate errors ignored if error is ignored during initial account setup in gnome-online-accounts
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
It was discovered evolution-ews does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
Debian
CVE-2019-3890: evolution-ews - It was discovered evolution-ews before 3.31.3 does not check the validity of SSL...
vendor_debian·2019·CVSS 8.1
CVE-2019-3890 [HIGH] CVE-2019-3890: evolution-ews - It was discovered evolution-ews before 3.31.3 does not check the validity of SSL...
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
Scope: local
bookworm: resolved (fixed in 3.30.5-1.1)
bullseye: resolved (fixed in 3.30.5-1.1)
forky: resolved (fixed in 3.30.5-1.1)
sid: resolved (fixed in 3.30.5-1.1)
trixie: resolved (fixed in 3.30.5-1.1)
GHSA
GHSA-mcq7-35g4-3c5q: It was discovered evolution-ews before 3
ghsa_unreviewed·2022-05-24
CVE-2019-3890 [HIGH] CWE-295 GHSA-mcq7-35g4-3c5q: It was discovered evolution-ews before 3
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
OSV
CVE-2019-3890: It was discovered evolution-ews before 3
osv·2019-08-01·CVSS 8.1
CVE-2019-3890 [HIGH] CVE-2019-3890: It was discovered evolution-ews before 3
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3890 evolution-ews: all certificate errors ignored if error is ignored during initial account setup in gnome-online-accounts
bugzilla·2019-02-18·CVSS 8.1
CVE-2019-3890 [HIGH] CVE-2019-3890 evolution-ews: all certificate errors ignored if error is ignored during initial account setup in gnome-online-accounts
CVE-2019-3890 evolution-ews: all certificate errors ignored if error is ignored during initial account setup in gnome-online-accounts
Evolution Exchange Web Services can silently ignore *all* certificate errors if configured to ignore an initial error in gnome-online-accounts creation. This renders transport security worse than zero as it does not even indicate (logs or UI) that a questionable certificate was presented, leaving the connection open to being viewed and modified.
Upstream issue:
https://gitlab.gnome.org/GNOME/evolution-ews/issues/36
Discussion:
Created evolution-ews tracking bugs for this issue:
Affects: fedora-all [bug 1678314]
---
Thanks for a bug report. The upstream bug had been marked as a duplicate of an older bug there. I'd prefer not to duplicate the work here
Bugzilla
CVE-2019-3890 evolution-ews: all certificate errors ignored if configured to ignore an initial error in gnome-online-accounts creation resulting in the connection open to being viewed and modified. [f
bugzilla·2019-02-18·CVSS 8.1
CVE-2019-3890 [HIGH] CVE-2019-3890 evolution-ews: all certificate errors ignored if configured to ignore an initial error in gnome-online-accounts creation resulting in the connection open to being viewed and modified. [f
CVE-2019-3890 evolution-ews: all certificate errors ignored if configured to ignore an initial error in gnome-online-accounts creation resulting in the connection open to being viewed and modified. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also ment
https://access.redhat.com/errata/RHSA-2019:3699https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3890https://gitlab.gnome.org/GNOME/evolution-ews/issues/27https://access.redhat.com/errata/RHSA-2019:3699https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3890https://gitlab.gnome.org/GNOME/evolution-ews/issues/27
2019-08-01
Published