Lucene search

K
osvGoogleOSV:GHSA-VWQQ-5VRC-XW9H
HistoryJun 05, 2020 - 2:15 p.m.

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

2020-06-0514:15:51
Google
osv.dev
35

0.002 Low

EPSS

Percentile

56.8%

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender prior to version 2.13.2. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.

References