CVE-2020-9488 vulnerability in Apache and Other Products
Published on April 27, 2020
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Products Associated with CVE-2020-9488
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-9488 are published in these products:
Affected Versions
Apache Log4j:- Version log4j-core 2.13.0 is affected.
- Version log4j-core and below 2.12.3 is affected.
Exploit Probability
EPSS
0.02%
Percentile
5.17%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.