CVE-2019-3890: High severity gnome evolution vulnerability
Evolution Exchange Web Services can silently ignore all certificate errors if configured to ignore an initial error in gnome-online-accounts creation. This renders transport security worse than zero as it does not even indicate (logs or UI) that a questionable certificate was presented, leaving the connection open to being viewed and modified.
Upstream issue:
https://gitlab.gnome.org/GNOME/evolution-ews/issues/36
Other sources
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3890?
CVE-2019-3890 is considered a critical vulnerability due to its potential to expose confidential information.
How do I fix CVE-2019-3890?
To fix CVE-2019-3890, upgrade to Evolution-ews version 3.31.3 or later.
What does CVE-2019-3890 affect?
CVE-2019-3890 affects versions of Evolution-ews prior to 3.31.3.
What is the risk associated with CVE-2019-3890?
The risk associated with CVE-2019-3890 is that attackers can intercept and obtain sensitive data by exploiting the SSL certificate validation flaw.
Who can be impacted by CVE-2019-3890?
Users of Evolution-ews prior to version 3.31.3 are at risk of being duped into connecting to malicious servers.