CVE-2020-9488

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

low 3.7 CVSS 3.1
Published: Apr 27, 2020
Modified: May 29, 2026
Vendor: Apache
Product: Log4J
Versions: 3.9m0p1,7.5.0.23.0,12.0.0.3.0,4.5,7.0,7.3.0,7.4.0,12.2.1.3.0,12.2.1.4.0,13.4.1.1

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

References

Related CVEs