VDB

CVE-2020-9488

CVE-2020-9488 PUBLISHED

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

EPSS 0.04% · 11.3th percentile

Risk Scores

EPSS Score
0.04%
11.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSapache-log4j22.10.0-2, 2.10.0-1, 0
Ubuntu:Pro:16.04:LTSapache-log4j20, 2.4-1, 2.4-2
Ubuntu:20.04:LTSapache-log4j22.15.0-0.20.04.1, 2.11.2-1, 2.11.1-2

Timeline

  • CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 19, 2021 EPSS Score
  • Jun 24, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Oct 1, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›