A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
2023-10-04T11:15:10.500
2024-11-21T08:35:29.373
Modified
CVSSv3.1: 7.4 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | data_grid | 8.0.0 | Yes |
Application | infinispan | hot_rod | - | Yes |