High severity8.1NVD Advisory· Published Aug 1, 2019· Updated Jun 17, 2026
CVE-2019-3890
CVE-2019-3890
Description
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- The Gnome Project/evolution-ewsv5Range: 3.31.3
<3.31.3+ 1 more
- (no CPE)range: <3.31.3
- cpe:2.3:a:gnome:evolution-ews:*:*:*:*:*:*:*:*range: <3.31.3
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- gitlab.gnome.org/GNOME/evolution-ews/issues/27nvdIssue TrackingThird Party Advisory
- access.redhat.com/errata/RHSA-2019:3699nvd
News mentions
0No linked articles in our index yet.