Описание
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A flaw was found in Apache Thrift C++ bindings. This vulnerability, caused by improper validation of certificates with host mismatch, could allow a remote attacker to disclose sensitive information.
Отчет
This vulnerability strictly impacts Confidentiality with zero effect on Integrity or Availability (C:H, I:N, A:N). Exploitation allows a remote attacker to conduct a man-in-the-middle (MitM) attack and intercept sensitive data transmitted over TLS if hostname validation fails. Red Hat rates this flaw with High Attack Complexity (AC:H) in contrast to NVD's Low Attack Complexity because successful exploitation requires specific, non-default network positioning to intercept traffic alongside a valid TLS certificate that triggers the host mismatch condition. Applications that do not use Apache Thrift C++ bindings for SSL/TLS encrypted client connections, or those operating exclusively over trusted private networks, are unaffected.
Меры по смягчению последствий
To mitigate this issue, restrict network access to systems utilizing Apache Thrift C++ bindings for SSL/TLS encrypted client connections to trusted private networks only. If feasible, avoid using Apache Thrift C++ bindings for SSL/TLS encrypted client connections in environments where man-in-the-middle attacks are a concern.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | thrift | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
Improper Validation of Certificate with Host Mismatch vulnerability in ...
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
EPSS
5.9 Medium
CVSS3