Skip to content
This repository has been archived by the owner on Dec 15, 2020. It is now read-only.

Fleet may expose SMTP credentials over insecure connection when LOGIN authentication is used

Low
directionless published GHSA-6g7f-8qm4-f7h8 May 30, 2019 · 1 comment

Package

No package listed

Affected versions

>2.0.2

Patched versions

2.1.2

Description

This advisory only effects installations using the LOGIN authentication method for SMTP (added in Fleet 2.0.2).

Impact

The implementation of LOGIN auth could expose SMTP credentials over an insecure connection if the server did not claim to support STARTTLS. This could allow an attacker to sniff or MITM SMTP traffic and obtain the credentials.

Patches

Effected users should immediately update to Fleet 2.1.2 and rotate the effected SMTP credentials.

Workarounds

If upgrade is not possible, do not use LOGIN auth for SMTP.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs