Описание
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
A flaw was found in Spring Boot. When configured to use an SSL (Secure Sockets Layer) bundle, the Elasticsearch auto-configuration component does not perform hostname verification when establishing a connection to the Elasticsearch server. An attacker on an adjacent network could exploit this by performing a man-in-the-middle attack. This could lead to the disclosure or modification of sensitive information exchanged between Spring Boot and the Elasticsearch server.
Меры по смягчению последствий
To mitigate the risk of man-in-the-middle attacks, ensure that network communication between Spring Boot applications and Elasticsearch servers is protected. This can be achieved by deploying these components on a trusted, isolated network segment or by implementing strict firewall rules to limit access to the Elasticsearch server only from authorized Spring Boot application instances.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | spring-boot | Fix deferred | ||
| Red Hat AMQ Clients | spring-boot | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-boot | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-boot | Fix deferred | ||
| Red Hat build of OptaPlanner 8 | spring-boot | Fix deferred | ||
| Red Hat Data Grid 8 | spring-boot | Fix deferred | ||
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Fix deferred | ||
| Red Hat Enterprise Linux 9 | log4j | Out of support scope | ||
| Red Hat Fuse 7 | spring-boot | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-boot | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.2 Medium
CVSS3
Связанные уязвимости
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
EPSS
4.2 Medium
CVSS3