Back

LOW

log4j: improper validation of certificate with host mismatch in SMTP appender

Published Apr 27, 2020

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Affected products

Remediation

Red Hat mitigation

Previous versions can set the system property mail.smtp.ssl.checkserveridentity to true to globally enable hostname verification for SMTPS connections.

Metrics

References (93)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 27, 2020
Updated May 29, 2026
Reserved Mar 1, 2020
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 25, 2020
GHSA-VWQQ-5VRC-XW9H