Date: Thu, 31 Oct 2024 10:51:25 GMT From: Vladimir Druzenko <vvd@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 331f33b5fe04 - main - security/vuxml: Add record for net/keycloak < 26.0.4 CVE-2021-44549 Message-ID: <202410311051.49VApPY4086926@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch main has been updated by vvd: URL: https://cgit.FreeBSD.org/ports/commit/?id=331f33b5fe04f74565ac89bd34aa1a2347eb0c5a commit 331f33b5fe04f74565ac89bd34aa1a2347eb0c5a Author: Matthias Wolf <freebsd@rheinwolf.de> AuthorDate: 2024-10-31 10:50:31 +0000 Commit: Vladimir Druzenko <vvd@FreeBSD.org> CommitDate: 2024-10-31 10:50:31 +0000 security/vuxml: Add record for net/keycloak < 26.0.4 CVE-2021-44549 PR: 282419 --- security/vuxml/vuln/2024.xml | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index f3e3444f0522..b3bbd1b07135 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,34 @@ + <vuln vid="fd538d14-5778-4764-b321-2ddd61a8a58f"> + <topic>keycloak -- Missing server identity checks when sending mails via SMTPS</topic> + <affects> + <package> + <name>keycloak</name> + <range><lt>26.0.4</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Red Hat reports:</p> + <blockquote cite="https://bugzilla.redhat.com/show_bug.cgi?id=2315808"> + <p>A vulnerability was found in Apache Sling Commons Messaging + Mail(angus-mail), which provides a simple interface for sending + emails via SMTPS in OSGi, does not offer an option to enable + server identity checks, leaving connections vulnerable to + "man-in-the-middle" attacks and can allow insecure email + communication.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2021-44549</cvename> + <url>https://www.cve.org/CVERecord?id=CVE-2021-44549</url> + </references> + <dates> + <discovery>2024-10-01</discovery> + <entry>2024-10-31</entry> + </dates> + </vuln> + <vuln vid="b73d1f2a-96de-11ef-9e71-00d8612f03c8"> <topic>librewolf -- Undefined behavior in selection node cache</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202410311051.49VApPY4086926>