5.9
CVSSv3

CVE-2024-8285

CVSSv4: NA | CVSSv3: 5.9 | CVSSv2: NA | VMScore: 690 | EPSS: 0.0006 | KEV: Not Included
Published: 30/08/2024 Updated: 13/11/2024

Vulnerability Summary

Hostname Verification Vulnerability in Kroxylicious Leading to Insecure TLS Connections

A vulnerability was discovered in Kroxylicious. When connecting to the upstream Kafka server with a TLS connection, it does not correctly verify the server's hostname. This leads to an insecure connection. To exploit this flaw, an attacker must perform a Man-in-the-Middle attack or compromise external systems like DNS or network routing. This attack is complex and requires high privileges since the attacker must access the Kroxylicious configuration or a peer system. If successful, this attack affects both data integrity and confidentiality.

Vulnerable Product Search on Vulmon Subscribe to Product

red hat streams for apache kafka 2.8.0

red hat streams for apache kafka

redhat kroxylicious -