Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-9488

Опубликовано: 27 апр. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 3.7

Описание

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

2.13.3-1
eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

released

2.16.0-0.20.04.1
esm-apps/jammy

not-affected

2.13.3-1
esm-apps/noble

not-affected

2.13.3-1
esm-infra-legacy/trusty

DNE

esm-infra/xenial

ignored

end of standard support, was needs-triage
focal

released

2.16.0-0.20.04.1

Показывать по

EPSS

Процентиль: 2%
0.00016
Низкий

4.3 Medium

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
nvd
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
debian
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j ...

CVSS3: 3.7
github
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

CVSS3: 3.7
fstec
около 5 лет назад

Уязвимость реализации класса SmtpAppender библиотеки журналирования Java-программ Log4j, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 2%
0.00016
Низкий

4.3 Medium

CVSS2

3.7 Low

CVSS3