Description
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1758
https://issues.redhat.com/browse/KEYCLOAK-13285
Related Vulnerabilities
CVE-2021-31411 Vulnerability in maven package com.vaadin:flow-server
CVE-2023-22832 Vulnerability in maven package org.apache.nifi:nifi-ccda-processors
CVE-2020-2138 Vulnerability in maven package org.jenkins-ci.plugins:cobertura
CVE-2021-41182 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2021-21696 Vulnerability in maven package org.jenkins-ci.main:jenkins-core