Описание
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory.
A flaw was found in Spring Boot's Cassandra auto-configuration. This vulnerability allows an adjacent attacker to bypass hostname verification during SSL (Secure Sockets Layer) connection establishment to Cassandra. This could enable a man-in-the-middle attack, potentially leading to unauthorized information disclosure, data tampering, or denial of service.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | spring-boot | Fix deferred | ||
| Red Hat AMQ Clients | spring-boot | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-boot | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-boot | Fix deferred | ||
| Red Hat build of OptaPlanner 8 | spring-boot | Fix deferred | ||
| Red Hat Data Grid 8 | spring-boot | Fix deferred | ||
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Fix deferred | ||
| Red Hat Enterprise Linux 9 | log4j | Out of support scope | ||
| Red Hat Fuse 7 | spring-boot | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-boot | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory.
Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verification
EPSS
6.4 Medium
CVSS3