Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
https://issues.redhat.com/browse/KEYCLOAK-13285
Related Vulnerabilities
CVE-2021-27524 Vulnerability in npm package braft-editor
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-spring
CVE-2022-45396 Vulnerability in maven package com.thalesgroup.hudson.plugins:sourcemonitor
CVE-2019-1003050 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-2190 Vulnerability in maven package org.jenkins-ci.plugins:script-security