Lucene search

K
redhatcveRedhat.comRH:CVE-2020-1758
HistoryMay 12, 2020 - 3:10 p.m.

CVE-2020-1758

2020-05-1215:10:25
redhat.com
access.redhat.com
14

0.001 Low

EPSS

Percentile

48.0%

A flaw was found in Keycloak, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

Mitigation

Turn off all kinds of email notifications including password reset mails.

0.001 Low

EPSS

Percentile

48.0%