CVE-2021-38373

MEDIUM

KDE KMail <19.12.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://nostarttls.secvuln.info
Mailing List, Vendor Advisory x_refsource_misc
https://bugs.kde.org/show_bug.cgi?id=423423

Scores

CVSS v3 5.3
EPSS 0.0016
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319 CWE-77
Status published
Products (1)
kde/kmail 19.12.3
Published Aug 10, 2021
Tracked Since Feb 18, 2026