Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.debian.org/security/2021/dsa-5020
https://security.netapp.com/advisory/ntap-20200504-0003/
https://lists.debian.org/debian-lts-announce/2021/12/msg00017.html
https://github.com/hkelley/PsNvdCvss
https://github.com/ManuelBravoR/NVD-CVE-Scanner-TelegramNotifier
https://github.com/ahmadk18361/Vulnerability-scanner-pipeline
https://github.com/arsalanraja987/java-log4j-cve-2020-9488
https://github.com/HynekPetrak/log4shell-finder