GHSA-h83p-72jv-g7vp
MODERATECVE-2024-8285A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the attacker needs to perform a Man-in-the-Middle attack or compromise any external systems, such as DNS or network routing configu
- Affected
- < 0.8.0
- Fixed in
- 0.8.0
- Weakness
- CWE-295
- Published
- 2024-08-31
- Source
- github