Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-9488

Опубликовано: 25 апр. 2020
Источник: redhat
CVSS3: 3.7

Описание

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Меры по смягчению последствий

Previous versions can set the system property mail.smtp.ssl.checkserveridentity to true to globally enable hostname verification for SMTPS connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7log4jFix deferred
Red Hat BPM Suite 6log4jOut of support scope
Red Hat Enterprise Linux 5log4jOut of support scope
Red Hat Enterprise Linux 6log4jOut of support scope
Red Hat Enterprise Linux 7log4jFix deferred
Red Hat Enterprise Linux 8parfait:0.5/log4j12Fix deferred
Red Hat JBoss A-MQ 6log4jOut of support scope
Red Hat JBoss BRMS 5log4jOut of support scope
Red Hat JBoss BRMS 6log4jOut of support scope
Red Hat JBoss Enterprise Application Platform 5log4j-coreOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1831139log4j: improper validation of certificate with host mismatch in SMTP appender

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
больше 6 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
nvd
больше 6 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
debian
больше 6 лет назад

Improper validation of certificate with host mismatch in Apache Log4j ...

CVSS3: 3.7
github
около 6 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

CVSS3: 3.7
fstec
больше 6 лет назад

Уязвимость реализации класса SmtpAppender библиотеки журналирования Java-программ Log4j, позволяющая нарушителю реализовать атаку типа «человек посередине»

3.7 Low

CVSS3