Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-6hg6-v5c8-fphq

5 месяцев назад

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

EPSS: Низкий
ubuntu логотип

CVE-2026-34477

5 месяцев назад

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element. Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value. A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met: * An SMTP, Socket, or Syslog appender is in use. * TLS is configured via a nested <Ssl> element. * The attacker can present a certificate issued by a CA trust...

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-34477

5 месяцев назад

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element. Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value. A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met: * An SMTP, Socket, or Syslog appender is in use. * TLS is configured via a nested <Ssl> element. * The attacker can present a certificate issued by a CA tr...

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-34477

5 месяцев назад

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element. Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value. A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met: * An SMTP, Socket, or Syslog appender is in use. * TLS is configured via a nested <Ssl> element. * The attacker can present a certificate issued by a

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2026-34477

5 месяцев назад

Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass

EPSS: Низкий
debian логотип

CVE-2026-34477

5 месяцев назад

The fix for CVE-2025-68161 https://logging.apache.org/security.html#C ...

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2026-10858

9 месяцев назад

Уязвимость параметра конфигурации verifyHostName библиотеки журналирования Apache Log4j Core, позволяющая нарушителю осуществить атаку типа «человек посередине»

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20260813-80-0050

около 1 месяца назад

Уязвимость log4j

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20260813-73-0050

около 1 месяца назад

Уязвимость log4j

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1843-1

4 месяца назад

Security update for log4j

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6hg6-v5c8-fphq

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-34477

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element. Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value. A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met: * An SMTP, Socket, or Syslog appender is in use. * TLS is configured via a nested <Ssl> element. * The attacker can present a certificate issued by a CA trust...

CVSS3: 5.9
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-34477

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element. Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value. A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met: * An SMTP, Socket, or Syslog appender is in use. * TLS is configured via a nested <Ssl> element. * The attacker can present a certificate issued by a CA tr...

CVSS3: 6.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-34477

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element. Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value. A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met: * An SMTP, Socket, or Syslog appender is in use. * TLS is configured via a nested <Ssl> element. * The attacker can present a certificate issued by a

CVSS3: 5.9
0%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-34477

Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass

0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-34477

The fix for CVE-2025-68161 https://logging.apache.org/security.html#C ...

CVSS3: 5.9
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-10858

Уязвимость параметра конфигурации verifyHostName библиотеки журналирования Apache Log4j Core, позволяющая нарушителю осуществить атаку типа «человек посередине»

CVSS3: 5.9
0%
Низкий
9 месяцев назад
redos логотип
ROS-20260813-80-0050

Уязвимость log4j

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260813-73-0050

Уязвимость log4j

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1843-1

Security update for log4j

4 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.