CVE-2021-26911: High severity thinkst canarytokens vulnerability
Published Feb 17, 2021
·Updated
core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.
Affected Software
3 affected components
Canarymail Canary Mail Iphone Os=3.20
Canarymail Canary Mail Iphone Os=3.21
Libmailcore Mailcore2=0.6.4
Remediation
Patch Available
Patch Available
Event History
Feb 17, 2021
CVE Published
via MITRE·08:54 PM
Data Sourced
via MITRE·08:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-26911.
2
What is the title of this vulnerability?
The title of this vulnerability is 'core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.'
3
What is the severity rating of CVE-2021-26911?
The severity rating of CVE-2021-26911 is high with a score of 7.4.
4
Which software versions are affected by this vulnerability?
Canary Mail versions 3.20 and 3.21, as well as Mailcore2 version 0.6.4, are affected by this vulnerability.
5
How can I fix this vulnerability?
To fix this vulnerability, update your Canary Mail to version 3.22 or later.