offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
{ "urgency": "low" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-4532.json"