CVE-2024-50624: Medium severity kmail vulnerability
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50624?
CVE-2024-50624 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks on cleartext HTTP connections.
How do I fix CVE-2024-50624?
To fix CVE-2024-50624, users should upgrade to KDE Kmail version 6.2.0 or later to ensure secure configurations.
Which versions of KDE Kmail are affected by CVE-2024-50624?
CVE-2024-50624 affects KDE Kmail versions prior to 6.2.0.
What kind of attack does CVE-2024-50624 enable?
CVE-2024-50624 enables man-in-the-middle attacks by allowing attackers to control the retrieval of mail server configuration.
Is the use of cleartext HTTP a concern in CVE-2024-50624?
Yes, the use of cleartext HTTP in CVE-2024-50624 poses a significant security risk as it can be intercepted by attackers.