Severity
7.4HIGH
EPSS
0.1%
top 67.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4

Description

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages2 packages

Mavenio.netty:netty-handler4.1.0.Final4.1.99.Final
NVDredhat/data_grid8.0.0

🔴Vulnerability Details

3
CVEList
Hotrod-client: hot rod client does not enable hostname validation when using tls that lead to a mitm attack2023-10-04
OSV
Withdrawn Advisory: Netty-handler does not validate host names by default2023-10-04
GHSA
Withdrawn Advisory: Netty-handler does not validate host names by default2023-10-04

📋Vendor Advisories

1
Red Hat
hotrod-client: Hot Rod client does not enable hostname validation when using TLS that lead to a MITM attack2023-08-29
CVE-2023-4586 (HIGH CVSS 7.4) | A vulnerability was found in the Ho | cvebase.io