Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-9488

Опубликовано: 27 апр. 2020
Источник: debian
EPSS Низкий

Описание

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache-log4j2fixed2.13.3-1package
apache-log4j2fixed2.15.0-1~deb10u1busterpackage
apache-log4j2no-dsajessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2020/04/25/1

  • https://issues.apache.org/jira/browse/LOG4J2-2819

  • https://gitbox.apache.org/repos/asf?p=logging-log4j2.git;h=6851b5083ef9610bae320bf07e1f24d2aa08851b (release-2.x)

  • https://gitbox.apache.org/repos/asf?p=logging-log4j2.git;h=fb91a3d71e2f3dadad6fd1beb2ab857f44fe8bbb (master)

EPSS

Процентиль: 2%
0.00016
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
redhat
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
nvd
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
github
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

CVSS3: 3.7
fstec
около 5 лет назад

Уязвимость реализации класса SmtpAppender библиотеки журналирования Java-программ Log4j, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 2%
0.00016
Низкий