Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
https://issues.redhat.com/browse/KEYCLOAK-13285
Related Vulnerabilities
CVE-2019-13990 Vulnerability in maven package org.quartz-scheduler:quartz
CVE-2023-24456 Vulnerability in maven package org.jenkins-ci.plugins:keycloak
CVE-2017-1000491 Vulnerability in npm package shiba
CVE-2022-23944 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2023-27900 Vulnerability in maven package org.jenkins-ci.main:jenkins-core