Skip to content
This repository has been archived by the owner on May 12, 2022. It is now read-only.

Upgrade the log4J library #287

Open
pushyamig opened this issue Jul 1, 2020 · 0 comments
Open

Upgrade the log4J library #287

pushyamig opened this issue Jul 1, 2020 · 0 comments

Comments

@pushyamig
Copy link
Contributor

moderate severity
Vulnerable versions: < 2.13.2
Patched version: 2.13.2
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant