CVE Database
/

CVE-2020-9488

Back to search

CVE-2020-9488

Published: Apr 27, 2020

Modified: May 29, 2026

PUBLISHED

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

VendorProductVersions

Apache

Apache Log4j

affected
log4j-core 2.13.0
affected
log4j-core - < 2.12.3

References

[kafka-users] 20210617 vulnerabilities
mailing-list
x_refsource_MLIST
DSA-5020
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now