golang: smtp.PlainAuth susceptible to man-in-the-middle password harvesting
Published Oct 5, 2017
5.9
MEDIUMCVSS 3.0
EPSS 1.10%
Description
An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the PLAIN auth scheme must only be used on network connections secured with TLS. The original implementation of smtp.PlainAuth in Go 1.0 enforced this requirement, and it was documented to do so. In 2013, upstream issue #5184, this was changed so that the server may decide whether PLAIN is acceptable. The result is that if you set up a man-in-the-middle SMTP server that doesn't advertise STARTTLS and does advertise that PLAIN auth is OK, the smtp.PlainAuth implementation sends the username and password.
Affected products
No data.
No data.
Red Hat Developer Tools
go-toolset-7-0:1.8-10.el7
Fixed · RHSA-2017:3463
Red Hat Developer Tools
go-toolset-7-golang-0:1.8.5-1.el7
Fixed · RHSA-2017:3463
Red Hat Enterprise Linux 7
golang-0:1.9.4-1.el7
Fixed · RHSA-2018:0878
Red Hat OpenShift Enterprise 3
golang
Affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
golang
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
golang
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Tools | go-toolset-7-0:1.8-10.el7 | Fixed | RHSA-2017:3463 |
| Red Hat Developer Tools | go-toolset-7-golang-0:1.8.5-1.el7 | Fixed | RHSA-2017:3463 |
| Red Hat Enterprise Linux 7 | golang-0:1.9.4-1.el7 | Fixed | RHSA-2018:0878 |
| Red Hat OpenShift Enterprise 3 | golang | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | golang | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | golang | Will not fix | n/a |
stdlib
Go
Introduced 1.1.0-0 Fixed 1.8.4stdlib
Go
Introduced 1.9.0-0 Fixed 1.9.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | stdlib | 1.1.0-0 | 1.8.4 |
| Go | stdlib | 1.9.0-0 | 1.9.1 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.10% (0.01105) | 64.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.10% (0.01105) | 61.39th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.16% (0.00159) | 34.18th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.29% (0.00285) | 69.59th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.29% (0.00285) | 67.86th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.29% (0.00285) | 64.72th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.42% (0.00422) | 70.23th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.18% (0.01183) | 61.76th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.18% (0.01183) | 35.15th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.86% (0.01865) | 48.06th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.86% (0.01865) | 0.00th | v1 |
References (12)
- http://www.securityfocus.com/bid/101197 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:3463 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:0878 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-15042 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1498867 Issue Tracking
- https://github.com/golang/go/issues/22134 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://golang.org/cl/68023 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://golang.org/cl/68210 x_refsource_CONFIRMVendor Advisory
- https://groups.google.com/d/msg/golang-dev/RinSE3EiJBI/kYL7zb07AgAJ x_refsource_CONFIRMMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-15042
- https://security.gentoo.org/glsa/201710-23 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-15042
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/101197 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/errata/RHSA-2017:3463 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2018:0878 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2017-15042 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1498867 | Issue Tracking | |
| https://github.com/golang/go/issues/22134 | x_refsource_CONFIRMIssue TrackingPatchVendor Advisory | |
| https://golang.org/cl/68023 | x_refsource_CONFIRMIssue TrackingPatchVendor Advisory | |
| https://golang.org/cl/68210 | x_refsource_CONFIRMVendor Advisory | |
| https://groups.google.com/d/msg/golang-dev/RinSE3EiJBI/kYL7zb07AgAJ | x_refsource_CONFIRMMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-15042 | ||
| https://security.gentoo.org/glsa/201710-23 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-15042 |
Change history (0)
No recorded changes yet.