Description
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
Remediation
References
Related Vulnerabilities
MySQL CVE-2016-0658 Vulnerability (CVE-2016-0658)
WordPress Plugin Uji Countdown Cross-Site Scripting (2.2)
MyBB Improper Privilege Management Vulnerability (CVE-2018-1000503)
Magento Improper Authorization Vulnerability (CVE-2020-24402)
WordPress Plugin Booking Calendar Multiple Vulnerabilities (6.2)