Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ3cXEtNXZyYy14dzlo

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender prior to version 2.13.2. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.

Permalink: https://github.com/advisories/GHSA-vwqq-5vrc-xw9h
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ3cXEtNXZyYy14dzlo
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 4 years ago
Updated: 10 months ago


CVSS Score: 3.7
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Identifiers: GHSA-vwqq-5vrc-xw9h, CVE-2020-9488
References: Blast Radius: 18.2

Affected Packages

maven:org.apache.logging.log4j:log4j-core
Dependent packages: 8,839
Dependent repositories: 82,953
Downloads:
Affected Version Ranges: < 2.3.2, >= 2.4.0, < 2.12.3, >= 2.13.0, < 2.13.2
Fixed in: 2.3.2, 2.12.3, 2.13.2
All affected versions: 2.0.1, 2.0.2, 2.3.1, 2.4.1, 2.6.1, 2.6.2, 2.8.1, 2.8.2, 2.9.0, 2.9.1, 2.10.0, 2.11.0, 2.11.1, 2.11.2, 2.12.0, 2.12.1, 2.12.2, 2.13.0, 2.13.1
All unaffected versions: 2.3.2, 2.12.3, 2.12.4, 2.13.2, 2.13.3, 2.14.0, 2.14.1, 2.15.0, 2.16.0, 2.17.0, 2.17.1, 2.17.2, 2.18.0, 2.19.0, 2.20.0, 2.21.0, 2.21.1, 2.22.0, 2.22.1, 2.23.0, 2.23.1, 2.24.0, 2.24.1
maven:org.apache.logging.log4j:log4j
Dependent packages: 64
Dependent repositories: 665
Downloads:
Affected Version Ranges: < 2.3.2, >= 2.4.0, < 2.12.3, >= 2.13.0, < 2.13.2
Fixed in: 2.3.2, 2.12.3, 2.13.2
All affected versions: 2.0.1, 2.0.2, 2.3.1, 2.4.1, 2.6.1, 2.6.2, 2.8.1, 2.8.2, 2.9.0, 2.9.1, 2.10.0, 2.11.0, 2.11.1, 2.11.2, 2.12.0, 2.12.1, 2.12.2, 2.13.0, 2.13.1
All unaffected versions: 2.3.2, 2.12.3, 2.12.4, 2.13.2, 2.13.3, 2.14.0, 2.14.1, 2.15.0, 2.16.0, 2.17.0, 2.17.1, 2.17.2, 2.18.0, 2.19.0, 2.20.0, 2.21.0, 2.21.1, 2.22.0, 2.22.1, 2.23.0, 2.23.1, 2.24.0, 2.24.1