CVE Vulnerabilities

CVE-2020-9488

Improper Certificate Validation

Published: Apr 27, 2020 | Modified: Nov 21, 2024
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Log4jApache2.0 (including)2.3.2 (excluding)
Log4jApache2.4 (including)2.12.3 (excluding)
Log4jApache2.13.0 (including)2.13.2 (excluding)
AMQ Clients 2.y for RHEL 6RedHatqpid-cpp-0:1.36.0-31.el6_10amq*
AMQ Clients 2.y for RHEL 6RedHatqpid-proton-0:0.32.0-1.el6_10*
AMQ Clients 2.y for RHEL 7RedHatqpid-cpp-0:1.36.0-31.el7amq*
AMQ Clients 2.y for RHEL 7RedHatqpid-proton-0:0.32.0-2.el7*
AMQ Clients 2.y for RHEL 8RedHatnodejs-rhea-0:1.0.24-1.el8*
AMQ Clients 2.y for RHEL 8RedHatqpid-proton-0:0.32.0-2.el8*
Red Hat Data GridRedHatlog4j-core*
Red Hat Data Grid 7.3.7RedHatlog4j*
Red Hat Fuse 7.10RedHatlog4j-core*
Red Hat Fuse 7.8.0RedHatlog4j*
Red Hat JBoss Data Virtualization 6.4.8.SP1RedHat*
Red Hat JBoss Data Virtualization 6.4.8.SP2RedHat*
RHDM 7.10.0RedHatlog4j-core*
RHPAM 7.10.1RedHatlog4j-core*
Text-Only RHOARRedHatlog4j*
Text-Only RHOARRedHatlog4j-core*
Apache-log4j2Ubuntubionic*
Apache-log4j2Ubuntueoan*
Apache-log4j2Ubuntuesm-apps/focal*
Apache-log4j2Ubuntuesm-infra/xenial*
Apache-log4j2Ubuntufocal*
Apache-log4j2Ubuntugroovy*
Apache-log4j2Ubuntutrusty*
Apache-log4j2Ubuntuupstream*
Apache-log4j2Ubuntuxenial*

Potential Mitigations

References