Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25078
HistoryApr 28, 2020 - 7:08 a.m.

Improper Validation Of Certificate

2020-04-2807:08:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.002 Low

EPSS

Percentile

56.8%

log4j-core is vulnerable to improper validation of certificate. It does not not verify the host name against the SSL/TLS certificate of an SMTPS connection during the certificate validation, allowing a man-in-the-middle to intercept the log messages sent.

References