cbcvebase.
CVE-2019-3890
published 2019-08-01

CVE-2019-3890: It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential…

PriorityP336high8.1CVSS 3.0
AVNACLPRNUIRSUCHIHAN
EPSS
0.99%
58.9th percentile
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianevolution-ews< evolution-ews 3.30.5-1.1 (bookworm)evolution-ews 3.30.5-1.1 (bookworm)
gnomeevolution-ews< 3.31.33.31.3
redhatenterprise_linux
redhatenterprise_linux
the_gnome_projectevolution-ews
the_gnome_projectevolution-ews>= 0 < 3.30.5-1.13.30.5-1.1
the_gnome_projectevolution-ews>= 0 < 3.30.5-1.13.30.5-1.1
the_gnome_projectevolution-ews>= 0 < 3.30.5-1.13.30.5-1.1
the_gnome_projectevolution-ews>= 0 < 3.30.5-1.13.30.5-1.1

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.