Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4586


A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.


Published

2023-10-04T11:15:10.500

Last Modified

2024-11-21T08:35:29.373

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat data_grid 8.0.0 Yes
Application infinispan hot_rod - Yes

References