Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
https://issues.redhat.com/browse/KEYCLOAK-13285
Related Vulnerabilities
CVE-2018-16487 Vulnerability in maven package org.webjars:lodash
CVE-2019-10301 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-plugin
CVE-2019-3894 Vulnerability in maven package org.wildfly:wildfly-ee
CVE-2019-10448 Vulnerability in maven package jenkins.xtc:extensivetesting
CVE-2015-0886 Vulnerability in maven package org.mindrot:jbcrypt