Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
https://issues.redhat.com/browse/KEYCLOAK-13285
Related Vulnerabilities
CVE-2022-45136 Vulnerability in maven package org.apache.jena:jena-sdb
CVE-2023-49068 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2018-19362 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-1466 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2023-30428 Vulnerability in maven package org.apache.pulsar:pulsar-broker