Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43869

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

A flaw was found in Apache Thrift. This vulnerability involves improper validation of a certificate with a host mismatch, which could allow a remote attacker to bypass security checks. By presenting a specially crafted certificate, an attacker may impersonate a legitimate server or client. This could lead to a security bypass, potentially enabling unauthorized access or information disclosure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2redhat-user-workloads/grafana-acm-212Not affected
Red Hat Advanced Cluster Management for Kubernetes 2redhat-user-workloads/grafana-acm-213Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat build of Apache Camel 4 for Quarkus 3libthriftAffected
Red Hat Data Grid 8libthriftNot affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Fuse 7libthriftWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2466660Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation

EPSS

Процентиль: 47%
0.00632
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVSS3: 7.3
nvd
3 месяца назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

msrc
3 месяца назад

Apache Thrift: TSSLTransportFactory.java hostname verification

CVSS3: 7.3
debian
3 месяца назад

Improper Validation of Certificate with Host Mismatch vulnerability in ...

CVSS3: 7.3
github
3 месяца назад

Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability

EPSS

Процентиль: 47%
0.00632
Низкий

7.3 High

CVSS3