Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
https://issues.redhat.com/browse/KEYCLOAK-13285
Related Vulnerabilities
CVE-2023-40338 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-folder
CVE-2023-45819 Vulnerability in maven package org.webjars.npm:tinymce
CVE-2020-8908 Vulnerability in maven package com.google.guava:guava
CVE-2020-14366 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2022-24820 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web