A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
Loading...
Loading...
Score 5.3 from GitHub Security Advisory published 2023-10-04. NVD baseline CVSS 7.4; sources differ by 2.1.
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
October 4, 2023
November 21, 2024
See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-4586
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.