Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1758

Опубликовано: 12 мая 2020
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

A flaw was found in Keycloak, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

Меры по смягчению последствий

Turn off all kinds of email notifications including password reset mails.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat OpenStack Platform 10 (Newton)keycloakOut of support scope
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign On 7.3.8FixedRHSA-2020:211212.05.2020
Red Hat Single Sign-On 7.3 for RHEL 6rh-sso7-keycloakFixedRHSA-2020:210612.05.2020
Red Hat Single Sign-On 7.3 for RHEL 7rh-sso7-keycloakFixedRHSA-2020:210712.05.2020
Red Hat Single Sign-On 7.3 for RHEL 8rh-sso7-keycloakFixedRHSA-2020:210812.05.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-297
https://bugzilla.redhat.com/show_bug.cgi?id=1812514keycloak: improper verification of certificate with host mismatch could result in information disclosure

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

CVSS3: 5.3
debian
больше 5 лет назад

A flaw was found in Keycloak in versions before 10.0.0, where it does ...

CVSS3: 5.9
github
почти 4 года назад

Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak

5.3 Medium

CVSS3