Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 PyPI

aiosmtpd STARTTLS unencrypted commands injection

GHSA-wgjv-9j3q-jhg8 · CVE-2024-34083

Published · Modified

Description

Summary

Servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a MitM attack.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes