QID 982986
QID 982986: Java (maven) Security Update for org.apache.logging.log4j:log4j-core (GHSA-vwqq-5vrc-xw9h)
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vwqq-5vrc-xw9h for updates pertaining to this vulnerability.
Vendor References
- GHSA-vwqq-5vrc-xw9h -
github.com/advisories/GHSA-vwqq-5vrc-xw9h
CVEs related to QID 982986
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vwqq-5vrc-xw9h | org.apache.logging.log4j:log4j |
|
|
| GHSA-vwqq-5vrc-xw9h | org.apache.logging.log4j:log4j-core |
|