GHSA-vwqq-5vrc-xw9hLowCVSS 3.7

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

Published
June 5, 2020
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender prior to version 2.13.2. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.

🎯 Affected products6

  • maven/org.apache.logging.log4j:log4j:>= 2.13.0, < 2.13.2
  • maven/org.apache.logging.log4j:log4j-core:>= 2.13.0, < 2.13.2
  • maven/org.apache.logging.log4j:log4j:>= 2.4.0, < 2.12.3
  • maven/org.apache.logging.log4j:log4j:< 2.3.2
  • maven/org.apache.logging.log4j:log4j-core:>= 2.4.0, < 2.12.3
  • maven/org.apache.logging.log4j:log4j-core:< 2.3.2

🔗 References (90)