HIGH
Hotrod-client: hot rod client does not enable hostname validation when using tls that lead to a mitm attack
Published Oct 4, 2023
7.4
HIGHCVSS 3.1
EPSS 0.55%
Description
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
Affected products
No data.
Configuration 2
- n/a
No data.
Red Hat Data Grid 8.4.6
hotrod-client
Fixed · RHSA-2023:7676
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Data Grid 8.4.6 | hotrod-client | Fixed | RHSA-2023:7676 |
No package ranges for this CVE.
Remediation
Vendor solution
No current mitigation is yet available for this vulnerability
Red Hat mitigation
No current mitigation is yet available for this vulnerability
References (6)
- https://access.redhat.com/errata/RHSA-2023:7676 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-4586 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2235564 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2654 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4586
- https://www.cve.org/CVERecord?id=CVE-2023-4586
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2023:7676 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2023-4586 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2235564 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2654 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-4586 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-4586 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 4, 2023
Updated Nov 20, 2025
Reserved Aug 29, 2023
Link CVE-2023-4586
CISA Vulnrichment
No data
GitHub
No data