Fedora Account System
Red Hat Associate
Red Hat Customer
A Cleartext Transmission of Sensitive Information vulnerability was found in the keycloak-services component. The issue exists in the SMTP configuration handling where setting starttls=true results in opportunistic TLS rather than mandatory TLS. An active Man-in-the-Middle attacker can strip the STARTTLS capability from the SMTP server response during the EHLO exchange. Because Keycloak does not enforce the upgrade to TLS, it proceeds to fall back to an unencrypted plaintext connection. This allows the attacker to capture SMTP authentication credentials and the full content of email messages transmitted by the server.