Severity
7.4
High severity
Details
- CVSS score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Overview
About vulnerability
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.Details
- Affected product:
- Apache ActiveMQ , Apache Hadoop , Apache Kafka , Apache Spark , Eclipse Jetty , Netty , Spring , artemis , async-http-client , avro , aws-sdk-java , azure-sdk-for-java , cassandra-java-driver , couchbase-jvm-clients , cxf , elasticsearch , grpc-netty , infinispan , java-driver , lettuce , lettuce-core , neo4j-java-driver , netty , rsocket-java , solr , tika , wildfly , zookeeper
- Affected packages:
- demo-async-rest-webapp @ 10.0.26 (+3849 more)