A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2654 | A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. |
Github GHSA |
GHSA-57m8-f3v5-hm5m | Withdrawn Advisory: Netty-handler does not validate host names by default |
Fixes
Solution
No solution given by the vendor.
Workaround
No current mitigation is yet available for this vulnerability
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T17:55:46.993Z
Reserved: 2023-08-29T04:57:10.685Z
Link: CVE-2023-4586
No data.
Status : Modified
Published: 2023-10-04T11:15:10.500
Modified: 2024-11-21T08:35:29.373
Link: CVE-2023-4586
OpenCVE Enrichment
No data.
EUVD
Github GHSA