Description
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
No current mitigation is yet available for this vulnerability
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2654 | A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. |
Github GHSA |
GHSA-57m8-f3v5-hm5m | Withdrawn Advisory: Netty-handler does not validate host names by default |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T17:55:46.993Z
Reserved: 2023-08-29T04:57:10.685Z
Link: CVE-2023-4586
No data.
Status : Modified
Published: 2023-10-04T11:15:10.500
Modified: 2024-11-21T08:35:29.373
Link: CVE-2023-4586
OpenCVE Enrichment
No data.
EUVD
Github GHSA