spring-boot-autoconfigure is vulnerable to Improper Validation of Certificate with Host Mismatch
50
Medium Risk
Spring Boot's mail auto-configuration does not enable SSL hostname verification by default for JavaMail connections. As a result, applications may fail to verify that the mail server's certificate matches the expected hostname, potentially allowing man-in-the-middle attacks when connecting to malicious or impersonated mail servers.
You are affected if you are using a version that falls within the vulnerable range. Applications that explicitly enable hostname verification through JavaMail properties are not affected.
spring-boot-autoconfigure is vulnerable to Improper Validation of Certificate with Host Mismatch in versions 3.4.0 - 3.4.16, 3.5.0 - 3.5.14 and 4.0.0 - 4.0.6.
Upgrade the org.springframework.boot:spring-boot-autoconfigure library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant