PT-2023-6590 · Netty+1 · Netty+1

Sandipan Roy

·

Publicado

2023-08-29

·

Atualizado

2023-12-06

·

CVE-2023-4586

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hot Rod client versions (affected versions not specified) Netty versions (affected versions not specified)
Description A security issue occurs as the Hot Rod client and Netty do not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. This issue can allow a remote attacker to execute a man-in-the-middle attack.
Recommendations For Hot Rod client, enable hostname validation when using TLS to prevent man-in-the-middle attacks. For Netty, users are advised to enable host name validation in their configurations by setting the protocol to "HTTPS" in the SSLParameters of the SSLEngine. A change in default behavior is expected in the 5.x release branch with no backport planned.

Correção

Improper Certificate Validation

Improper Authentication

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07355
CVE-2023-4586
GHSA-57M8-F3V5-HM5M

Produtos afetados

Hot Rod
Netty