PT-2019-10390 · Mailpile · Mailpile
Jackdca
·
Published
2019-08-08
·
Updated
2020-08-24
·
CVE-2018-20954
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mailpile versions prior to 1.0.0rc4
Description
The issue concerns the "Security and Privacy" Encryption feature in Mailpile, which fails to exclude disabled, revoked, and expired keys.
Recommendations
For versions prior to 1.0.0rc4, update to version 1.0.0rc4 or later to resolve the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mailpile