CVE-2020-1758
published 2020-05-15CVE-2020-1758: A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.91%
55.9th percentile
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 10.0.0 | 10.0.0 |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: improper verification of certificate with host mismatch could result in information disclosure
vendor_redhat·2020-05-12·CVSS 5.3
CVE-2020-1758 [MEDIUM] CWE-297 keycloak: improper verification of certificate with host mismatch could result in information disclosure
keycloak: improper verification of certificate with host mismatch could result in information disclosure
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
A flaw was found in Keycloak, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Mitigation: Turn off all kinds of email notifications including password reset mails.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat OpenShift Application Runtimes) - Not affected
Package: keycloak (Red Hat OpenStack Platfo
OSV
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak
osv·2022-02-09
CVE-2020-1758 [MEDIUM] Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
GHSA
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak
ghsa·2022-02-09
CVE-2020-1758 [MEDIUM] CWE-295 Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
No detection rules found.
No public exploits indexed.
2020-05-15
Published