← Back

CVE-2020-1758

nvd nist
Published: May 15, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

Affected (2)

2 products
Keycloak
Openstack
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.0.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10

References (4)

Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: secalert@redhat.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory

Timeline

No history available yet.