Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://issues.redhat.com/browse/KEYCLOAK-13285
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
Related Vulnerabilities
CVE-2013-6407 Vulnerability in maven package org.apache.solr:solr-core
CVE-2021-3856 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2022-36888 Vulnerability in maven package com.datapipe.jenkins.plugins:hashicorp-vault-plugin
CVE-2020-2123 Vulnerability in maven package org.jenkins-ci.plugins:radargun