MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15047
Reference (s):
- https://bugs.kde.org/show_bug.cgi?id=423453
- https://gerrit.vesnicky.cesnet.cz/r/1035