Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
https://issues.redhat.com/browse/KEYCLOAK-13285
Related Vulnerabilities
CVE-2023-40342 Vulnerability in maven package org.jenkins-ci.plugins:flaky-test-handler
CVE-2018-20677 Vulnerability in npm package bootstrap
CVE-2023-24438 Vulnerability in maven package org.jenkins-ci.plugins:jira-steps
CVE-2022-20612 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2012-6153 Vulnerability in maven package commons-httpclient:commons-httpclient