CVE-2023-4586
published 2023-10-04CVE-2023-4586: A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly…
PriorityP339high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.45%
36.3th percentile
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | data_grid | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hotrod-client: Hot Rod client does not enable hostname validation when using TLS that lead to a MITM attack
vendor_redhat·2023-08-29·CVSS 7.4
CVE-2023-4586 [HIGH] CWE-20 hotrod-client: Hot Rod client does not enable hostname validation when using TLS that lead to a MITM attack
hotrod-client: Hot Rod client does not enable hostname validation when using TLS that lead to a MITM attack
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
Mitigation: No current mitigation is yet available for this vulnerability
OSV
Withdrawn Advisory: Netty-handler does not validate host names by default
osv·2023-10-04
CVE-2023-4586 [MEDIUM] Withdrawn Advisory: Netty-handler does not validate host names by default
Withdrawn Advisory: Netty-handler does not validate host names by default
## Withdrawn Advisory
This advisory has been withdrawn because the underlying vulnerability only concerns Red Hat's Hot Rod client, which is not in one of the GitHub Advisory Database's [supported ecosystems](https://github.com/github/advisory-database/blob/main/README.md#supported-ecosystems). This link is maintained to preserve external references.
## Original Description
Netty-handler has been found to no validate hostnames when using TLS in its default configuration. As a result netty-handler is vulnerable to man-in-the-middle attacks. Users would need to set the protocol to "HTTPS" in the SSLParameters of the SSLEngine to opt in to host name validation. A change in default behavior is expected in the `5.x` rel
GHSA
Withdrawn Advisory: Netty-handler does not validate host names by default
ghsa·2023-10-04
CVE-2023-4586 [MEDIUM] CWE-295 Withdrawn Advisory: Netty-handler does not validate host names by default
Withdrawn Advisory: Netty-handler does not validate host names by default
## Withdrawn Advisory
This advisory has been withdrawn because the underlying vulnerability only concerns Red Hat's Hot Rod client, which is not in one of the GitHub Advisory Database's [supported ecosystems](https://github.com/github/advisory-database/blob/main/README.md#supported-ecosystems). This link is maintained to preserve external references.
## Original Description
Netty-handler has been found to no validate hostnames when using TLS in its default configuration. As a result netty-handler is vulnerable to man-in-the-middle attacks. Users would need to set the protocol to "HTTPS" in the SSLParameters of the SSLEngine to opt in to host name validation. A change in default behavior is expected in the `5.x` rel
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:7676https://access.redhat.com/security/cve/CVE-2023-4586https://bugzilla.redhat.com/show_bug.cgi?id=2235564https://access.redhat.com/errata/RHSA-2023:7676https://access.redhat.com/security/cve/CVE-2023-4586https://bugzilla.redhat.com/show_bug.cgi?id=2235564
2023-10-04
Published