PT-2023-6590 · Netty+1 · Netty+1

Sandipan Roy

·

Published

2023-08-29

·

Updated

2023-12-06

·

CVE-2023-4586

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hot Rod client versions (affected versions not specified) Netty versions (affected versions not specified)
Description A security issue occurs as the Hot Rod client and Netty do not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. This issue can allow a remote attacker to execute a man-in-the-middle attack.
Recommendations For Hot Rod client, enable hostname validation when using TLS to prevent man-in-the-middle attacks. For Netty, users are advised to enable host name validation in their configurations by setting the protocol to "HTTPS" in the SSLParameters of the SSLEngine. A change in default behavior is expected in the 5.x release branch with no backport planned.

Fix

Improper Certificate Validation

Improper Authentication

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07355
CVE-2023-4586
GHSA-57M8-F3V5-HM5M

Affected Products

Hot Rod
Netty