CVE-2020-9488 PUBLISHED

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

EPSS 0.03% · 8.4th percentile

Risk Scores

EPSS Score
0.03%
8.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSapache-log4j22.8.2-2, 2.10.0-1, 2.10.0-2
Ubuntu:Pro:16.04:LTSapache-log4j20, 2.2-1, 2.4-1
Ubuntu:20.04:LTSapache-log4j20, 2.11.1-2, 2.11.2-1

Timeline

References

Open in Interactive Console →