Hostname Verification Vulnerability in Kroxylicious Leading to Insecure TLS Connections
A vulnerability was discovered in Kroxylicious. When connecting to the upstream Kafka server with a TLS connection, it does not correctly verify the server's hostname. This leads to an insecure connection. To exploit this flaw, an attacker must perform a Man-in-the-Middle attack or compromise external systems like DNS or network routing. This attack is complex and requires high privileges since the attacker must access the Kroxylicious configuration or a peer system. If successful, this attack affects both data integrity and confidentiality.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
red hat streams for apache kafka 2.8.0 |
||
red hat streams for apache kafka |
||
redhat kroxylicious - |