Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c597-f74m-jgc2

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

< 10.0.0

10.0.0

EPSS

Процентиль: 48%
0.00254
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-295
CWE-297

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

CVSS3: 5.3
nvd
больше 5 лет назад

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

CVSS3: 5.3
debian
больше 5 лет назад

A flaw was found in Keycloak in versions before 10.0.0, where it does ...

EPSS

Процентиль: 48%
0.00254
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-295
CWE-297