CVE-2019-3890
—CVSS 3.0
8.1 high
EPSS
<1%p60
Published
()
Modified
Description
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
In the news0 stories
No ingested article mentions this CVE yet.